Diamond Sleet
2023-04-18 • Microsoft • How Microsoft names threat actors
Microsoft tracks this actor as Diamond Sleet, the name it adopted in April 2023 for the North Korea-based group formerly designated ZINC, which other researchers have linked to activity described as Labyrinth Chollima, Lazarus, and Temp.Hermit. The group is assessed to pursue espionage, theft of personal and corporate data, financial gain, and destructive attacks against corporate networks, targeting media, information technology services, and defense organizations worldwide. Microsoft has reported its targeting of security researchers, weaponizing of open-source software, and a supply chain compromise of a German software provider. In October 2023 it exploited a JetBrains TeamCity remote-code-execution vulnerability to deploy a custom backdoor and DLL search-order-hijacking payloads that established command-and-control channels and dumped credentials from memory. The following month it distributed a trojanized installer for a legitimate CyberLink Corp. application, signed with a valid certificate and hosted on CyberLink's own update infrastructure, compromising over one hundred devices across Japan, Taiwan, Canada, and the United States. The group relies on malware built exclusively for its own use and has a history of exfiltrating data and compromising software build environments.
-
60
Related Actors
-
690
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Diamond Sleet reports only