"Diamond Sleet supply chain compromise distributes a modified CyberLink installer" published by Microsoft. #LambLoad, #CyberLink, #DiamondSleet, #CTI, #OSINT, #LAZARUS https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/
Diamond Sleet supply chain compromise distributes a modified CyberLink installer | Microsoft Security Blog
Microsoft has uncovered a supply chain attack by the threat actor Diamond Sleet (ZINC) involving a malicious variant of an application developed by CyberLink Corp. This malicious file is a legitimate CyberLink application installer that has been modified to include malicious code that downloads, decrypts, and loads a second-stage payload. The file, which was signed using a valid certificate issued to CyberLink Corp., is hosted on legitimate update infrastructure owned by the organization.