CyberLink installer served LambLoad
Diamond Sleet modified CyberLink's Promeo installer and signed it with a valid CyberLink certificate. LambLoad reached more than 100 devices before Microsoft and CyberLink responded.
Story
CyberLink's update infrastructure carried a poisoned installer in October and November 2023. The file was a legitimate CyberLink Promeo downloader modified to include LambLoad, then signed with a valid CyberLink Corp. certificate and hosted from CyberLink-owned update URLs.
Microsoft attributed the operation with high confidence to Diamond Sleet, the North Korean group formerly tracked as ZINC. The campaign touched more than 100 devices in Japan, Taiwan, Canada, the United States, and other countries. Microsoft notified CyberLink and affected Defender for Endpoint customers, reported the payload host to GitHub, and added the abused CyberLink certificate to its disallowed certificate list.
LambLoad first checked the host date against a configured execution window. It also looked for security tooling associated with CrowdStrike, FireEye, and Tanium. If the checks failed, the installer ran the expected CyberLink software and skipped the malicious path.
When the checks passed, the loader fetched a second stage hidden inside a fake PNG from GitHub Pages, Imgur, or a compromised web server. The payload was carved, decrypted, and launched in memory, then called back to compromised infrastructure for instructions. Microsoft had not identified hands-on-keyboard activity at publication, but treated launched code as full device compromise.
Affected Artifacts
- Observed
- 2023-10-20 to 2023-11-22
- Compromised Versions
- Unknown
- Fixed
- Not listed
- Hashes
-
- sha256:166d1a6ddcde4e859a89c2c825cd3c8c953a86bfa92b343de7e5bfbfb5afb8be
- sha256:089573b3a1167f387dcdad5e014a5132e998b2c89bff29bcf8b06dd497d4e63d
- sha256:915c2495e03ff7408f11a2a197f23344004c533ff87db4b807cc937f80c217a1
- Evidence
- distribution: update.cyberlink.com/Retail/Promeo/RDZCMSFY1ELY/CyberLink_Promeo_Downloader.exe, distribution: update.cyberlink.com/Retail/Patch/Promeo/DL/RDZCMSFY1ELY/CyberLink_Promeo_Downloader.exe, mirror: microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer, mirror: virustotal.com/gui/file/166d1a6ddcde4e859a89c2c825cd3c8c953a86bfa92b343de7e5bfbfb5afb8be , +21 more
- Affected CyberLink scope covered specific application installers active around October and November 2023, including Promeo reporting.
Incident Context
- Motive
- Espionage Data Theft
- Attribution
- State
- Cause
- Vendor Infrastructure Compromise
- Transitive
- No
- Actor
- Diamond Sleet
- User Impact
- 100
External References
- Diamond Sleet supply chain compromise distributes a modified CyberLink installermicrosoft.com
- North Korean attack on CyberLink impacted devices around the world, Microsoft saystherecord.media
- North Korean Hackers Distribute Malicious CyberLink Installer in Supply Chain Attackthehackernews.com
- Microsoft says North Korean hackers breached CyberLink in supply chain attackbleepingcomputer.com
Source record: proprietary/cyberlink/meta.yaml