By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechziTechziTechzi
  • Home
  • Community
    • Our Review
    • Join Our Slack community
    • Referral: Richieee
    • Referral: 6 for 6
  • Publications
    • Special Report: SE Asian Startup Funding
    • Top 30 Most Funded Southeast Asia Startups
  • Agencies
  • About
    • About us
    • Contact
Search
© 2023 Techzi . All Rights Reserved.
Reading: Hackers Hijack Software Update to Target CyberLink Users
Share
Font ResizerAa
TechziTechzi
Font ResizerAa
Search
  • Home
  • Community
    • Our Review
    • Join Our Slack community
    • Referral: Richieee
    • Referral: 6 for 6
  • Publications
    • Special Report: SE Asian Startup Funding
    • Top 30 Most Funded Southeast Asia Startups
  • Agencies
  • About
    • About us
    • Contact
Have an existing account? Sign In
Follow US
© 2023 Techzi . All Rights Reserved.
SaaS

Hackers Hijack Software Update to Target CyberLink Users

Archy Ehan
Last updated: February 12, 2024 1:49 pm
Archy Ehan
Share
2 Min Read
SHARE
  • North Korea hackers infiltrated CyberLink to infect 400 million users via malware-laced software updates.
  • Exploiting valid certificates, the attackers compromised CyberLink’s infrastructure to distribute malicious code undetected.
  • Microsoft notified affected parties but supply chain breach shows susceptibility.

Contents
State-Sponsored Hackers Target CyberLinkPopular Software Developer CyberLink Breached: 400 Million Users at RiskCyberLink Hit by Hackers in Late October

State-Sponsored Hackers Target CyberLink

North Korean state-sponsored hackers have compromised Taiwanese software developer CyberLink to distribute malware to its users as part of a supply chain attack. 

According to Microsoft threat researchers, the attackers injected malicious code into legitimate CyberLink software updates distributed to over 100 victims across several countries. 

The tainted updates were signed with a valid CyberLink certificate to avoid detection. 

Popular Software Developer CyberLink Breached: 400 Million Users at Risk

CyberLink is known for multimedia and facial recognition programs like PowerDVD. The company has shipped over 400 million applications worldwide. By infiltrating CyberLink’s infrastructure, the hackers were able to access a vast pool of potential targets. 

Microsoft attributes this attack to a North Korean group called Diamond Sleet with high confidence. Diamond Sleet has previously targeted IT, defence, and media organizations, focusing on cyber espionage and data theft. 

CyberLink Hit by Hackers in Late October

The attack was first spotted in late October 2023 but may have started earlier. Microsoft has not yet observed direct hacking activity but notes that Diamond Sleet frequently attempts to establish persistent access to victim networks to steal data. 

Microsoft has notified CyberLink of the compromise, but it’s unknown if the company has taken action. 

For now, Microsoft is warning its Defender clients who were affected and has blocked the hackers’ digital certificates. 

The supply chain breach illustrates how even reputable software vendors can be compromised by nation-state groups to cast a wider net for cyber espionage and surveillance.

TAGGED:div5

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook X Copy Link Print
Share
Previous Article Bard Gains Deeper Understanding of YouTube Content
Next Article Gates: 3-Day Work Week “Probably OK” in AI-Powered Future

Subscribe to our newsletter to get our newest articles instantly

Please enable JavaScript in your browser to complete this form.
=

Stay Connected

XFollow
InstagramFollow
YoutubeSubscribe
TiktokFollow

Latest News

Techzi is Pausing
Media December 24, 2024
Twitch Pioneer Emmett Shear Launches Mysterious AI Venture
AI December 24, 2024
OpenAI CEO Labels Musk a ‘Bully’ in Latest Tech Titan Clash
AI December 24, 2024
AI Revolution Could Spark Live Entertainment Boom
Culture December 24, 2024

You Might also Like

Logistics

Waresix Streamlines Tech Team Amidst Growth Trajectory

February 23, 2024
Social Media

Twitch Unmutes Trump’s Account for 2024 Election Buzz

July 25, 2024
Social Media

TikTok’s Fate Hangs in the Balance, US Senate Passes Potential Ban

April 26, 2024
Startups

AI-Powered Fish Feeding Frenzy, eFishery Nets $30M from HSBC

June 5, 2024
AI

Quora Raises $75M To Power AI Chat Platform Poe And Its Creator Economy

February 17, 2024
AI

Google’s AI Now Writes 25% of Company Code

November 4, 2024
Social Media

The Most Engaging Social Network Isn’t TikTok According to Neil Patel

February 12, 2024
Social Media

Leaked Images Reveal Musk’s Grok Chatbot Coming to Twitter’s Paid Tier

February 12, 2024
StartupsVC

Antler Invests $750K into Six Early-Stage Indonesian Startups

February 12, 2024
AIHealth-Tech

Tencent Bets on AI and Social Media to Transform China’s Healthcare Sector

February 17, 2024
Strategy

Kraft Heinz Spices Up Supply Chain Management with AI-Powered ‘Lighthouse

September 2, 2024
Strategy

The Power of Breaking Down Everything Into Discrete Tasks

June 28, 2024

Techzi

SE Asian tech news: Free & Comprehensive. Read more

Quick Links

  • Logistics
  • Marketplace
  • Mobility
  • Startups
  • VC
  • Food tech
  • Gaming
  • Health-Tech
  • Media
  • Social Media
  • SaaS
  • Travel

Quick Links

  • AI
  • Edutech
  • Climate
  • Creators
  • Crypto & Web3
  • Culture
  • Deep Tech
  • e-Commerce
  • FAANG
  • Fashion
  • Fintech

Techzi Tech Newsletter

FREE and Curated by Tech Insiders

Legal

Privacy Policy

Terms & conditions

TechziTechzi
Follow US
© 2024 Techzi . All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?