home.social

#diamondsleet — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #diamondsleet, aggregated by home.social.

fetched live
  1. Diamond Sleet supply chain compromise distributes a modified CyberLink installer

    Researchers uncovered a supply chain attack by the North Korea-based threat actor Diamond Sleet (ZINC) involving a malicious variant of an application developed by CyberLink Corp., a software company that develops multimedia software products. This malicious file is a legitimate CyberLink application installer that has been modified to include malicious code that downloads, decrypts, and loads a second-stage payload. The file, which was signed using a valid certificate issued to CyberLink Corp., is hosted on legitimate update infrastructure owned by CyberLink and includes checks to limit the time window for execution and evade detection by security products.

    Pulse ID: 655f0ab585a20bff0cac8b7c
    Pulse Link: otx.alienvault.com/pulse/655f0
    Pulse Author: AlienVault
    Created: 2023-11-23 08:17:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #NorthKorea #IAM #DiamondSleet #AlienVault