By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechziTechziTechzi
  • Home
  • Community
    • Our Review
    • Join Our Slack community
    • Referral: Richieee
    • Referral: 6 for 6
  • Publications
    • Special Report: SE Asian Startup Funding
    • Top 30 Most Funded Southeast Asia Startups
  • Agencies
  • About
    • About us
    • Contact
Search
© 2023 Techzi . All Rights Reserved.
Reading: Hackers Hijack Software Update to Target CyberLink Users
Share
Font ResizerAa
TechziTechzi
Font ResizerAa
Search
  • Home
  • Community
    • Our Review
    • Join Our Slack community
    • Referral: Richieee
    • Referral: 6 for 6
  • Publications
    • Special Report: SE Asian Startup Funding
    • Top 30 Most Funded Southeast Asia Startups
  • Agencies
  • About
    • About us
    • Contact
Have an existing account? Sign In
Follow US
© 2023 Techzi . All Rights Reserved.
SaaS

Hackers Hijack Software Update to Target CyberLink Users

Archy Ehan
Last updated: February 12, 2024 1:49 pm
Archy Ehan
Share
2 Min Read
SHARE
  • North Korea hackers infiltrated CyberLink to infect 400 million users via malware-laced software updates.
  • Exploiting valid certificates, the attackers compromised CyberLink’s infrastructure to distribute malicious code undetected.
  • Microsoft notified affected parties but supply chain breach shows susceptibility.

Contents
State-Sponsored Hackers Target CyberLinkPopular Software Developer CyberLink Breached: 400 Million Users at RiskCyberLink Hit by Hackers in Late October

State-Sponsored Hackers Target CyberLink

North Korean state-sponsored hackers have compromised Taiwanese software developer CyberLink to distribute malware to its users as part of a supply chain attack. 

According to Microsoft threat researchers, the attackers injected malicious code into legitimate CyberLink software updates distributed to over 100 victims across several countries. 

The tainted updates were signed with a valid CyberLink certificate to avoid detection. 

Popular Software Developer CyberLink Breached: 400 Million Users at Risk

CyberLink is known for multimedia and facial recognition programs like PowerDVD. The company has shipped over 400 million applications worldwide. By infiltrating CyberLink’s infrastructure, the hackers were able to access a vast pool of potential targets. 

Microsoft attributes this attack to a North Korean group called Diamond Sleet with high confidence. Diamond Sleet has previously targeted IT, defence, and media organizations, focusing on cyber espionage and data theft. 

CyberLink Hit by Hackers in Late October

The attack was first spotted in late October 2023 but may have started earlier. Microsoft has not yet observed direct hacking activity but notes that Diamond Sleet frequently attempts to establish persistent access to victim networks to steal data. 

Microsoft has notified CyberLink of the compromise, but it’s unknown if the company has taken action. 

For now, Microsoft is warning its Defender clients who were affected and has blocked the hackers’ digital certificates. 

The supply chain breach illustrates how even reputable software vendors can be compromised by nation-state groups to cast a wider net for cyber espionage and surveillance.

TAGGED:div5

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook X Copy Link Print
Share
Previous Article Bard Gains Deeper Understanding of YouTube Content
Next Article Gates: 3-Day Work Week “Probably OK” in AI-Powered Future

Subscribe to our newsletter to get our newest articles instantly

Please enable JavaScript in your browser to complete this form.
=

Stay Connected

XFollow
InstagramFollow
YoutubeSubscribe
TiktokFollow

Latest News

Techzi is Pausing
Media December 24, 2024
Twitch Pioneer Emmett Shear Launches Mysterious AI Venture
AI December 24, 2024
OpenAI CEO Labels Musk a ‘Bully’ in Latest Tech Titan Clash
AI December 24, 2024
AI Revolution Could Spark Live Entertainment Boom
Culture December 24, 2024

You Might also Like

Strategy

Adding a Work Trial to Your Interview process

February 12, 2024
Mobility

GoTo Zeroes in on Profitability

February 12, 2024
AIFood tech

Targeted Ads Coming Soon to Smart Grocery Carts

February 12, 2024
Social Media

Durex India’s Website Blunder Exposes Customer Data

September 3, 2024
AI

James Green’s Prediction on ChatGPT Business

February 17, 2024
AI

SK Telecom and Singtel Join Forces to Shape the Future of Telecommunications

July 15, 2024
Media

Streaming Executives Predict a Return to TV’s Roots

June 26, 2024
AIEdutech

Arizona State Becomes First University to Partner With OpenAI

February 12, 2024
e-CommerceSocial Media

TikTok Gets Crafty, Mulls Indonesian E-Commerce Tie-Ups After Online Shop Shutdown

February 12, 2024
Strategy

Rockbird Media’s HR Leaders & HR Tech Strategy Meeting to Navigate the Human-Tech Frontier in Indonesia

November 8, 2024
Fintech

F88 Bounces Back, Vietnamese Financial Firm Reports $1.2M Profit in Q1 2024

June 3, 2024
Startups

India’s Wow Momo Foods Banks $42M To Fuel Cloud Kitchen and Retail Expansion

February 12, 2024

Techzi

SE Asian tech news: Free & Comprehensive. Read more

Quick Links

  • Logistics
  • Marketplace
  • Mobility
  • Startups
  • VC
  • Food tech
  • Gaming
  • Health-Tech
  • Media
  • Social Media
  • SaaS
  • Travel

Quick Links

  • AI
  • Edutech
  • Climate
  • Creators
  • Crypto & Web3
  • Culture
  • Deep Tech
  • e-Commerce
  • FAANG
  • Fashion
  • Fintech

Techzi Tech Newsletter

FREE and Curated by Tech Insiders

Legal

Privacy Policy

Terms & conditions

TechziTechzi
Follow US
© 2024 Techzi . All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?