Diamond Sleet supply chain compromise distributes a modified CyberLink installer

2023-11-22 Microsoft

https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/

Thumbnail for Diamond Sleet supply chain compromise distributes a modified CyberLink installer

Microsoft attributes a CyberLink supply-chain compromise to Diamond Sleet, a North Korea-based actor also tracked as ZINC, Temp.Hermit, or Labyrinth Chollima. The malicious file was a legitimate CyberLink installer signed with a valid CyberLink certificate and hosted on legitimate update infrastructure, but modified to download, decrypt, and load the LambLoad second-stage payload. Microsoft observed impact on more than 100 devices across Japan, Taiwan, Canada, and the United States, and the payload communicated with infrastructure previously compromised by Diamond Sleet. LambLoad checked execution timing and avoided hosts running selected security products before retrieving payloads masquerading as PNG files from Stack Imgur, webville.net, or GitHub Pages. The compromise is significant because it shows a DPRK actor abusing trusted vendor software, code signing, and update channels to reach IT, media, defense, and other targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0a08d3601636378f0a7d64fd09e4a13b 2023-11-22 2023-11-22
HASH 915c2495e03ff7408f11a2a197f2334… 2023-11-22 2023-11-22
HASH 166d1a6ddcde4e859a89c2c825cd3c8… 2023-11-22 2023-11-22
HASH 8aa3877ab68ba56dabc2f2802e813dc… 2023-11-22 2023-11-22
HASH 089573b3a1167f387dcdad5e014a513… 2023-11-22 2023-11-22
URL https://cldownloader.github.io/… 2023-11-22 2023-11-22
URL https://mantis.jancom.pl/bluema… 2023-11-22 2023-11-22
URL https://i.stack.imgur.com/NDTUM… 2023-11-22 2023-11-22
URL https://zeduzeventos.busqueabus… 2023-11-22 2023-11-22
URL https://www.webville.net/images… 2023-11-22 2023-11-22
URL https://zeduzeventos.busqueabus… 2023-11-22 2023-11-22
URL https://update.cyberlink.com/Re… 2023-11-22 2023-11-22
URL https://update.cyberlink.com/Re… 2023-11-22 2023-11-22
DOMAIN cldownloader.github.io 2023-11-22 2023-11-22
DOMAIN update.cyberlink.com 2023-11-22 2023-11-22
DOMAIN zeduzeventos.busqueabuse.com 2023-11-22 2023-11-22
DOMAIN mantis.jancom.pl 2023-11-22 2023-11-22
DOMAIN i.stack.imgur.com 2023-11-22 2023-11-22

Related Actors

Related Reports

« Back