Microsoft says North Korean hackers Lazarus breached Taiwanese multimedia software company CyberLink and trojanized one of its installers to distribute malware in a supply chain attack targeting victims around the world.

According to Microsoft, malicious activity believed to be linked to CyberLink's trojanized installer file appeared on October 20, 2023.
This trojanized installer was hosted on a legitimate CyberLink update infrastructure and has so far been detected on more than 100 devices worldwide, in countries such as Japan, Taiwan, Canada, and the United States.
See also: Lazarus hackers target users with fake interviews via trojanized VNC apps
Microsoft believes this supply chain attack is linked to the North Korean cyberespionage group Diamond Sleet (also known as ZINC, Labyrinth Chollima, and Lazarus).
The second-stage payload observed during the investigation of this attack interacts with infrastructure that the hackers themselves had previously compromised.
“ Diamond Sleet/Lazarus used a legitimate code signing certificate issued to CyberLink Corp. to sign the malicious executable ,” the company said
“This certificate has been added to Microsoft's disallowed certificate list to protect customers from future malicious use of the certificate.“.
Microsoft researchers are tracking the trojanized software and related payloads as LambLoad (a malware downloader and loader).
LambLoad targets systems that are not protected by FireEye, CrowdStrike, or Tanium security software.
See also: Lazarus and Andariel hackers exploit TeamCity bug for network breaches

If this protection is not present, the malware connects to one of three command-and-control (C2) servers to retrieve a second-stage payload hidden within a file presented as a file PNG using the static User-Agent 'Microsoft Internet Explorer'.
“The PNG file contains an embedded payload within a fake PNG external header that is decrypted and executed in memory,” Microsoft says.
This is a common attack method used by North Korean Lazarus hackers. These hackers often infect legitimate cryptocurrency software to steal crypto assets.
Although Microsoft has not yet identified the real purpose of the attacks, Lazarus hackers are known for: stealing sensitive data from compromised systems, infiltrating software development environments, exploiting further victims, and attempting to gain long-term access to victims' environments.
After identifying the supply chain attack, Microsoft notified software provider CyberLink and notified Microsoft Defender and Endpoint affected by the attack.
Microsoft also reported the attack to GitHub, which removed the second-stage payload.
See also: Lazarus hackers use new LightlessCan malware

Lazarus hackers
The Lazarus hackers are a group supported by the government and have been active since at least 2009. They target organizations around the world, primarily financial institutions, media companies, and government agencies.
Hackers have also targeted security researchers and are behind large-scale attacks and promoting fake job interviews to spread malware.
One of the most well-known and dangerous incidents attributed to Lazarus hackers is the WannaCry in 2017. This attack hit many organizations and businesses globally, encrypting their files and demanding a ransom for their decryption.
Another incident worth mentioning is the attack on Sony Pictures in 2014. Hackers managed to leak sensitive information, causing serious damage to the company.
Source: www.bleepingcomputer.com
