ZINC weaponizing open-source software

2022-09-29 Microsoft

https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/

Thumbnail for ZINC weaponizing open-source software

Microsoft attributed a 2022 social-engineering campaign to ZINC, a North Korea-based group now tracked as Diamond Sleet, targeting employees in media, defense and aerospace, and IT services organizations in the US, UK, India, and Russia. The operators built trust on LinkedIn, moved conversations to WhatsApp, and delivered malicious payloads through weaponized legitimate open-source software including PuTTY, KiTTY, TightVNC, Sumatra PDF Reader, and muPDF/Subliminal Recording installers. Microsoft observed the ZetaNile/BLINDINGCAN malware family using DLL search order hijacking, encrypted or packed implant DLLs, and HTTP C2 requests to compromised domains. The campaign is significant because it combines recruiter-style social engineering with widely used tools, giving ZINC a scalable path to espionage, data theft, financial gain, and potential destructive access across multiple sectors.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hurricanepub.com 2022-09-14 2023-09-29
DOMAIN turnscor.com 2020-12-15 2023-09-29
DOMAIN olidhealth.com 2022-09-29 2023-03-09
HASH 14f736b7df6a35c29eaed82a47fc0a2… 2022-09-29 2022-11-03
HASH 37e30dc2faaabaf93f0539ffbde0324… 2022-09-29 2022-11-03
IPv4 44.238.74.84 2022-09-29 2022-11-03
IPv4 137.184.15.189 2022-09-14 2022-11-03
IPv4 172.93.201.253 2022-04-26 2022-11-03
HASH e1ecf0f7bd90553baaa83dcdc177e1d… 2022-09-29 2022-09-29
HASH c3a9b30b6a313f289297c9a36730db6d 2022-09-29 2022-09-29
HASH c5a470cdf6f57125a8671f6b8843149… 2022-09-29 2022-09-29
HASH 71beb4252e93291c7b14dfcb4cbb5d5… 2022-09-29 2022-09-29
HASH 63cddab76e9d63e3cbea421b6073427… 2022-09-29 2022-09-29
HASH 0ce1241a44557aa438f27bc6d4aca246 2022-09-29 2022-09-29
DOMAIN recruitment.raystechserv.com 2022-09-29 2022-09-29
DOMAIN cats.runtimerec.com 2022-09-29 2022-09-29
HASH aaad412aeb0f98c2c27bb817682f086… 2022-09-14 2022-09-29
HASH 1492fa04475b89484b5b0a02e6ba3e5… 2022-09-14 2022-09-29
DOMAIN elite4print.com 2020-04-28 2022-09-29

Related Actors

Related Reports

« Back