Proprietary 2023-10-20 · 33 days ·Backdoor, Remote Access

CyberLink installer served LambLoad

Diamond Sleet modified CyberLink's Promeo installer and signed it with a valid CyberLink certificate. LambLoad reached more than 100 devices before Microsoft and CyberLink responded.

Story

CyberLink's update infrastructure carried a poisoned installer in October and November 2023. The file was a legitimate CyberLink Promeo downloader modified to include LambLoad, then signed with a valid CyberLink Corp. certificate and hosted from CyberLink-owned update URLs.

Microsoft attributed the operation with high confidence to Diamond Sleet, the North Korean group formerly tracked as ZINC. The campaign touched more than 100 devices in Japan, Taiwan, Canada, the United States, and other countries. Microsoft notified CyberLink and affected Defender for Endpoint customers, reported the payload host to GitHub, and added the abused CyberLink certificate to its disallowed certificate list.

LambLoad first checked the host date against a configured execution window. It also looked for security tooling associated with CrowdStrike, FireEye, and Tanium. If the checks failed, the installer ran the expected CyberLink software and skipped the malicious path.

When the checks passed, the loader fetched a second stage hidden inside a fake PNG from GitHub Pages, Imgur, or a compromised web server. The payload was carved, decrypted, and launched in memory, then called back to compromised infrastructure for instructions. Microsoft had not identified hands-on-keyboard activity at publication, but treated launched code as full device compromise.

Affected Artifacts

Promeo

· cyberlink.com · Binary Archive
Observed
2023-10-20 to 2023-11-22
Compromised Versions
Unknown
Fixed
Not listed
Hashes
  • sha256:166d1a6ddcde4e859a89c2c825cd3c8c953a86bfa92b343de7e5bfbfb5afb8be
  • sha256:089573b3a1167f387dcdad5e014a5132e998b2c89bff29bcf8b06dd497d4e63d
  • sha256:915c2495e03ff7408f11a2a197f23344004c533ff87db4b807cc937f80c217a1
  • Affected CyberLink scope covered specific application installers active around October and November 2023, including Promeo reporting.

Incident Context

Motive
Espionage Data Theft
Attribution
State
Cause
Vendor Infrastructure Compromise
Transitive
No
Actor
Diamond Sleet
User Impact
100

External References

Source record: proprietary/cyberlink/meta.yaml