North Korean state-backed hackers are distributing malicious versions of legitimate applications developed by Taiwanese software maker CyberLink to target downstream customers. North Korean hackers have breached CyberLink and distributed the company's modified installation files as part of a widespread supply chain attack, Microsoft's threat intelligence team said on Wednesday.

learn more:

https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/

CyberLink is a Taiwan-based software company that mainly develops multimedia software such as PowerDVD and artificial intelligence facial recognition technology. According to the company's website, CyberLink has more than 200 patented technologies and has shipped more than 400 million applications worldwide.

Microsoft said it discovered suspicious activity as early as October 20, 2023, related to a modified CyberLink installer, which the company tracked as "LambLoad." To date, Microsoft has detected the Trojan installer on more than 100 devices in multiple countries, including Japan, Taiwan, Canada, and the United States.

Microsoft said the file was hosted on legitimate update infrastructure owned by CyberLink, and the attackers used a legitimate code signing certificate issued to CyberLink to sign the malicious executable. Microsoft's Threat Intelligence Team said: "This certificate has been added to Microsoft's list of disallowed certificates to protect customers from future malicious use of this certificate."

The company noted that the second-stage payload observed during this campaign interacted with infrastructure previously compromised by the same group of threat actors.

Microsoft attributed the attack with "a high degree of confidence" to a group it tracks called DiamondSleet, a North Korean state actor with ties to the notorious Lazarus hacking group. The group was observed targeting organizations in the information technology, defense and media sectors. According to Microsoft, it focuses primarily on espionage, financial gain, and enterprise network disruption.

Microsoft noted that DiamondSleet attackers typically steal data from compromised systems, infiltrate software build environments, work their way downstream to exploit more victims, and attempt to gain persistent access to the victim's environment.

Microsoft said it notified CyberLink of the supply chain compromise but did not say whether it had received a response or whether CyberLink had taken any action based on the company's findings. The company also notified Microsoft Defender for Endpoint customers who were affected by the attack.