ZINC weaponizing open-source software
2022-09-29 • Microsoft •
https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/
Microsoft attributed a 2022 social-engineering campaign to ZINC, a North Korea-based group now tracked as Diamond Sleet, targeting employees in media, defense and aerospace, and IT services organizations in the US, UK, India, and Russia. The operators built trust on LinkedIn, moved conversations to WhatsApp, and delivered malicious payloads through weaponized legitimate open-source software including PuTTY, KiTTY, TightVNC, Sumatra PDF Reader, and muPDF/Subliminal Recording installers. Microsoft observed the ZetaNile/BLINDINGCAN malware family using DLL search order hijacking, encrypted or packed implant DLLs, and HTTP C2 requests to compromised domains. The campaign is significant because it combines recruiter-style social engineering with widely used tools, giving ZINC a scalable path to espionage, data theft, financial gain, and potential destructive access across multiple sectors.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | hurricanepub.com | 2022-09-14 | 2023-09-29 |
| DOMAIN | turnscor.com | 2020-12-15 | 2023-09-29 |
| DOMAIN | olidhealth.com | 2022-09-29 | 2023-03-09 |
| HASH | 14f736b7df6a35c29eaed82a47fc0a2… | 2022-09-29 | 2022-11-03 |
| HASH | 37e30dc2faaabaf93f0539ffbde0324… | 2022-09-29 | 2022-11-03 |
| IPv4 | 44.238.74.84 | 2022-09-29 | 2022-11-03 |
| IPv4 | 137.184.15.189 | 2022-09-14 | 2022-11-03 |
| IPv4 | 172.93.201.253 | 2022-04-26 | 2022-11-03 |
| HASH | e1ecf0f7bd90553baaa83dcdc177e1d… | 2022-09-29 | 2022-09-29 |
| HASH | c3a9b30b6a313f289297c9a36730db6d | 2022-09-29 | 2022-09-29 |
| HASH | c5a470cdf6f57125a8671f6b8843149… | 2022-09-29 | 2022-09-29 |
| HASH | 71beb4252e93291c7b14dfcb4cbb5d5… | 2022-09-29 | 2022-09-29 |
| HASH | 63cddab76e9d63e3cbea421b6073427… | 2022-09-29 | 2022-09-29 |
| HASH | 0ce1241a44557aa438f27bc6d4aca246 | 2022-09-29 | 2022-09-29 |
| DOMAIN | recruitment.raystechserv.com | 2022-09-29 | 2022-09-29 |
| DOMAIN | cats.runtimerec.com | 2022-09-29 | 2022-09-29 |
| HASH | aaad412aeb0f98c2c27bb817682f086… | 2022-09-14 | 2022-09-29 |
| HASH | 1492fa04475b89484b5b0a02e6ba3e5… | 2022-09-14 | 2022-09-29 |
| DOMAIN | elite4print.com | 2020-04-28 | 2022-09-29 |