By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechziTechziTechzi
  • Home
  • Community
    • Our Review
    • Join Our Slack community
    • Referral: Richieee
    • Referral: 6 for 6
  • Publications
    • Special Report: SE Asian Startup Funding
    • Top 30 Most Funded Southeast Asia Startups
  • Agencies
  • About
    • About us
    • Contact
Search
© 2023 Techzi . All Rights Reserved.
Reading: Hackers Hijack Software Update to Target CyberLink Users
Share
Font ResizerAa
TechziTechzi
Font ResizerAa
Search
  • Home
  • Community
    • Our Review
    • Join Our Slack community
    • Referral: Richieee
    • Referral: 6 for 6
  • Publications
    • Special Report: SE Asian Startup Funding
    • Top 30 Most Funded Southeast Asia Startups
  • Agencies
  • About
    • About us
    • Contact
Have an existing account? Sign In
Follow US
© 2023 Techzi . All Rights Reserved.
SaaS

Hackers Hijack Software Update to Target CyberLink Users

Archy Ehan
Last updated: February 12, 2024 1:49 pm
Archy Ehan
Share
2 Min Read
SHARE
  • North Korea hackers infiltrated CyberLink to infect 400 million users via malware-laced software updates.
  • Exploiting valid certificates, the attackers compromised CyberLink’s infrastructure to distribute malicious code undetected.
  • Microsoft notified affected parties but supply chain breach shows susceptibility.

Contents
State-Sponsored Hackers Target CyberLinkPopular Software Developer CyberLink Breached: 400 Million Users at RiskCyberLink Hit by Hackers in Late October

State-Sponsored Hackers Target CyberLink

North Korean state-sponsored hackers have compromised Taiwanese software developer CyberLink to distribute malware to its users as part of a supply chain attack. 

According to Microsoft threat researchers, the attackers injected malicious code into legitimate CyberLink software updates distributed to over 100 victims across several countries. 

The tainted updates were signed with a valid CyberLink certificate to avoid detection. 

Popular Software Developer CyberLink Breached: 400 Million Users at Risk

CyberLink is known for multimedia and facial recognition programs like PowerDVD. The company has shipped over 400 million applications worldwide. By infiltrating CyberLink’s infrastructure, the hackers were able to access a vast pool of potential targets. 

Microsoft attributes this attack to a North Korean group called Diamond Sleet with high confidence. Diamond Sleet has previously targeted IT, defence, and media organizations, focusing on cyber espionage and data theft. 

CyberLink Hit by Hackers in Late October

The attack was first spotted in late October 2023 but may have started earlier. Microsoft has not yet observed direct hacking activity but notes that Diamond Sleet frequently attempts to establish persistent access to victim networks to steal data. 

Microsoft has notified CyberLink of the compromise, but it’s unknown if the company has taken action. 

For now, Microsoft is warning its Defender clients who were affected and has blocked the hackers’ digital certificates. 

The supply chain breach illustrates how even reputable software vendors can be compromised by nation-state groups to cast a wider net for cyber espionage and surveillance.

TAGGED:div5

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook X Copy Link Print
Share
Previous Article Bard Gains Deeper Understanding of YouTube Content
Next Article Gates: 3-Day Work Week “Probably OK” in AI-Powered Future

Subscribe to our newsletter to get our newest articles instantly

Please enable JavaScript in your browser to complete this form.
=

Stay Connected

XFollow
InstagramFollow
YoutubeSubscribe
TiktokFollow

Latest News

Techzi is Pausing
Media December 24, 2024
Twitch Pioneer Emmett Shear Launches Mysterious AI Venture
AI December 24, 2024
OpenAI CEO Labels Musk a ‘Bully’ in Latest Tech Titan Clash
AI December 24, 2024
AI Revolution Could Spark Live Entertainment Boom
Culture December 24, 2024

You Might also Like

Startups

Better HR Secures Bridge Funding for Southeast Asian Expansion

June 8, 2024
Fashion

The Fashion Disruptor Looking to Strike IPO Gold

February 12, 2024
VC

Olympic Gold Medalist Joseph Schooling Dives into Venture Capital

April 4, 2024
Social Media

Snowflake Aims to 10X Revenue on Way to $10B Through Vertical Focus

February 12, 2024
Crypto & Web3Gaming

Web3 Giants Join Forces: Animoca Brands and EVG Unite

June 7, 2024
Travel

Yanolja Gears Up for $400M US IPO, Valuation Soars to $9B

June 12, 2024
FAANGMedia

Netflix Revamps Infamous ‘Keeper Test’ in Latest Culture Memo Update

July 2, 2024
Food tech

Swiggy’s IPO Feast: Serving Up $1.25B on the Menu

May 1, 2024
AI

OpenAI Unveils ChatGPT’s Advanced Voice Mode to Select Users

August 5, 2024
AI

Runway Launches $5M Fund for AI-Generated Films

October 2, 2024
CreatorsStrategy

Sahil Bloom Has Learned 33 Lessons on His 33rd Birthday

February 12, 2024
AgTechStartups

Jiva’s Green Revolution: Agritech Startup Sprouts 62% Revenue Growth

August 14, 2024

Techzi

SE Asian tech news: Free & Comprehensive. Read more

Quick Links

  • Logistics
  • Marketplace
  • Mobility
  • Startups
  • VC
  • Food tech
  • Gaming
  • Health-Tech
  • Media
  • Social Media
  • SaaS
  • Travel

Quick Links

  • AI
  • Edutech
  • Climate
  • Creators
  • Crypto & Web3
  • Culture
  • Deep Tech
  • e-Commerce
  • FAANG
  • Fashion
  • Fintech

Techzi Tech Newsletter

FREE and Curated by Tech Insiders

Legal

Privacy Policy

Terms & conditions

TechziTechzi
Follow US
© 2024 Techzi . All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?