By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechziTechziTechzi
  • Home
  • Community
    • Our Review
    • Join Our Slack community
    • Referral: Richieee
    • Referral: 6 for 6
  • Publications
    • Special Report: SE Asian Startup Funding
    • Top 30 Most Funded Southeast Asia Startups
  • Agencies
  • About
    • About us
    • Contact
Search
© 2023 Techzi . All Rights Reserved.
Reading: Hackers Hijack Software Update to Target CyberLink Users
Share
Font ResizerAa
TechziTechzi
Font ResizerAa
Search
  • Home
  • Community
    • Our Review
    • Join Our Slack community
    • Referral: Richieee
    • Referral: 6 for 6
  • Publications
    • Special Report: SE Asian Startup Funding
    • Top 30 Most Funded Southeast Asia Startups
  • Agencies
  • About
    • About us
    • Contact
Have an existing account? Sign In
Follow US
© 2023 Techzi . All Rights Reserved.
SaaS

Hackers Hijack Software Update to Target CyberLink Users

Archy Ehan
Last updated: February 12, 2024 1:49 pm
Archy Ehan
Share
2 Min Read
SHARE
  • North Korea hackers infiltrated CyberLink to infect 400 million users via malware-laced software updates.
  • Exploiting valid certificates, the attackers compromised CyberLink’s infrastructure to distribute malicious code undetected.
  • Microsoft notified affected parties but supply chain breach shows susceptibility.

Contents
State-Sponsored Hackers Target CyberLinkPopular Software Developer CyberLink Breached: 400 Million Users at RiskCyberLink Hit by Hackers in Late October

State-Sponsored Hackers Target CyberLink

North Korean state-sponsored hackers have compromised Taiwanese software developer CyberLink to distribute malware to its users as part of a supply chain attack. 

According to Microsoft threat researchers, the attackers injected malicious code into legitimate CyberLink software updates distributed to over 100 victims across several countries. 

The tainted updates were signed with a valid CyberLink certificate to avoid detection. 

Popular Software Developer CyberLink Breached: 400 Million Users at Risk

CyberLink is known for multimedia and facial recognition programs like PowerDVD. The company has shipped over 400 million applications worldwide. By infiltrating CyberLink’s infrastructure, the hackers were able to access a vast pool of potential targets. 

Microsoft attributes this attack to a North Korean group called Diamond Sleet with high confidence. Diamond Sleet has previously targeted IT, defence, and media organizations, focusing on cyber espionage and data theft. 

CyberLink Hit by Hackers in Late October

The attack was first spotted in late October 2023 but may have started earlier. Microsoft has not yet observed direct hacking activity but notes that Diamond Sleet frequently attempts to establish persistent access to victim networks to steal data. 

Microsoft has notified CyberLink of the compromise, but it’s unknown if the company has taken action. 

For now, Microsoft is warning its Defender clients who were affected and has blocked the hackers’ digital certificates. 

The supply chain breach illustrates how even reputable software vendors can be compromised by nation-state groups to cast a wider net for cyber espionage and surveillance.

TAGGED:div5

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook X Copy Link Print
Share
Previous Article Bard Gains Deeper Understanding of YouTube Content
Next Article Gates: 3-Day Work Week “Probably OK” in AI-Powered Future

Subscribe to our newsletter to get our newest articles instantly

Please enable JavaScript in your browser to complete this form.
=

Stay Connected

XFollow
InstagramFollow
YoutubeSubscribe
TiktokFollow

Latest News

Techzi is Pausing
Media December 24, 2024
Twitch Pioneer Emmett Shear Launches Mysterious AI Venture
AI December 24, 2024
OpenAI CEO Labels Musk a ‘Bully’ in Latest Tech Titan Clash
AI December 24, 2024
AI Revolution Could Spark Live Entertainment Boom
Culture December 24, 2024

You Might also Like

Strategy

Managing Inputs vs. Managing Outputs

September 16, 2024
Fintech

This Profitable Fintech Hit $100 Million Revenue

February 12, 2024
AI

AI’s Billion-Dollar Gamble: The Race to Profitability

August 23, 2024
e-CommerceFashion

Meesho Mania, India’s Social Commerce Juggernaut Raises $275M

May 17, 2024
SaaS

Qiscus raises $2m

February 12, 2024
AIStartups

Locofy Launches AI Design-to-Code with “Lightning” Product

February 17, 2024
Startups

Boston Consulting Group (BCG)’s Report on Thailand’s Startup Ecosystem

February 12, 2024
Crypto & Web3

Cake Group Survives Co-Founder Clash, For Now

May 1, 2024
Startups

Rippling CEO Champions Hands-On Leadership Style

August 22, 2024
VC

Seedefy: A Platform Designed to Make VCs’ Lives Easy

February 29, 2024
Gaming

Animoca Teams With Ubisoft To Boost Web3 Gaming Initiatives

February 12, 2024
StartupsVC

Seed Fund FEBE Ventures Raises $75M for Second Fund

February 12, 2024

Techzi

SE Asian tech news: Free & Comprehensive. Read more

Quick Links

  • Logistics
  • Marketplace
  • Mobility
  • Startups
  • VC
  • Food tech
  • Gaming
  • Health-Tech
  • Media
  • Social Media
  • SaaS
  • Travel

Quick Links

  • AI
  • Edutech
  • Climate
  • Creators
  • Crypto & Web3
  • Culture
  • Deep Tech
  • e-Commerce
  • FAANG
  • Fashion
  • Fintech

Techzi Tech Newsletter

FREE and Curated by Tech Insiders

Legal

Privacy Policy

Terms & conditions

TechziTechzi
Follow US
© 2024 Techzi . All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?