Diamond Sleet supply chain compromise distributes a modified CyberLink installer
2023-11-22 • Microsoft •
Microsoft attributes a CyberLink supply-chain compromise to Diamond Sleet, a North Korea-based actor also tracked as ZINC, Temp.Hermit, or Labyrinth Chollima. The malicious file was a legitimate CyberLink installer signed with a valid CyberLink certificate and hosted on legitimate update infrastructure, but modified to download, decrypt, and load the LambLoad second-stage payload. Microsoft observed impact on more than 100 devices across Japan, Taiwan, Canada, and the United States, and the payload communicated with infrastructure previously compromised by Diamond Sleet. LambLoad checked execution timing and avoided hosts running selected security products before retrieving payloads masquerading as PNG files from Stack Imgur, webville.net, or GitHub Pages. The compromise is significant because it shows a DPRK actor abusing trusted vendor software, code signing, and update channels to reach IT, media, defense, and other targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0a08d3601636378f0a7d64fd09e4a13b | 2023-11-22 | 2023-11-22 |
| HASH | 915c2495e03ff7408f11a2a197f2334… | 2023-11-22 | 2023-11-22 |
| HASH | 166d1a6ddcde4e859a89c2c825cd3c8… | 2023-11-22 | 2023-11-22 |
| HASH | 8aa3877ab68ba56dabc2f2802e813dc… | 2023-11-22 | 2023-11-22 |
| HASH | 089573b3a1167f387dcdad5e014a513… | 2023-11-22 | 2023-11-22 |
| URL | https://cldownloader.github.io/… | 2023-11-22 | 2023-11-22 |
| URL | https://mantis.jancom.pl/bluema… | 2023-11-22 | 2023-11-22 |
| URL | https://i.stack.imgur.com/NDTUM… | 2023-11-22 | 2023-11-22 |
| URL | https://zeduzeventos.busqueabus… | 2023-11-22 | 2023-11-22 |
| URL | https://www.webville.net/images… | 2023-11-22 | 2023-11-22 |
| URL | https://zeduzeventos.busqueabus… | 2023-11-22 | 2023-11-22 |
| URL | https://update.cyberlink.com/Re… | 2023-11-22 | 2023-11-22 |
| URL | https://update.cyberlink.com/Re… | 2023-11-22 | 2023-11-22 |
| DOMAIN | cldownloader.github.io | 2023-11-22 | 2023-11-22 |
| DOMAIN | update.cyberlink.com | 2023-11-22 | 2023-11-22 |
| DOMAIN | zeduzeventos.busqueabuse.com | 2023-11-22 | 2023-11-22 |
| DOMAIN | mantis.jancom.pl | 2023-11-22 | 2023-11-22 |
| DOMAIN | i.stack.imgur.com | 2023-11-22 | 2023-11-22 |