The CyberLink Installer Supply Chain Attack

Updated 5 Oct 2026 · Incident date 20 Oct 2023 · vendor binary

PackageCyberLink Promeo installer (CyberLink_Promeo_Downloader.exe), signed with a valid CyberLink Corp certificate
FileCyberLink_Promeo_Downloader.exe

In October 2023, a modified CyberLink Promeo installer (CyberLink_Promeo_Downloader.exe) carried hidden loader code. It had a valid CyberLink Corp. signature and came from CyberLink's own update servers. Microsoft linked it to the North Korean group Diamond Sleet and published its analysis on 22 November 2023.

Microsoft found the file on over 100 devices in Japan, Taiwan, Canada, and the United States. This page lists what the file did, the indicators Microsoft published, and how to check a Windows machine.

What happened

Attackers replaced a legitimate CyberLink installer with a trojanized copy on CyberLink's update infrastructure. Microsoft first saw suspicious activity on 20 October 2023.

The file was a modified version of the CyberLink Promeo downloader. Microsoft says it was signed with a valid certificate from CyberLink Corp., issued by DigiCert SHA2 Assured ID Code Signing CA. Microsoft added that certificate to its disallowed list. BleepingComputer reports that CyberLink and Defender for Endpoint customers received notices, and that GitHub removed the second-stage payload.

The installer added new behavior. It first checks that the local date and time fall inside a preset execution period. It then looks for three security products. If it finds csfalconservice.exe (CrowdStrike Falcon), xagt.exe (FireEye), or taniumclient.exe (Tanium), it stops. If none run, it connects to a remote server with the static User-Agent Microsoft Internet Explorer.

The server returns a file that looks like a PNG image. The file has a fake PNG header around an embedded payload. The loader cuts out the payload, decrypts it, and runs it in memory. Microsoft names the loader family LambLoad.

At the time of reporting, Microsoft saw no hands-on-keyboard activity after the compromise. BleepingComputer notes that Lazarus-linked groups have used this type of access for data theft and for entry into build environments.

Affected versions

Microsoft names one affected file and does not give a CyberLink product version number. The affected file is the Promeo downloader below.

A valid signature does not prove the file is clean. The attackers signed the bad file with the real CyberLink certificate.

Indicators of compromise

Microsoft published file hashes, URLs, and detection names. Defang the URLs before you search logs.

How to check

Compare the SHA-256 of any copy of the installer with the hash Microsoft published. Run this in PowerShell on the machine that holds the file.

Get-FileHash .\CyberLink_Promeo_Downloader.exe -Algorithm SHA256

If the hash equals 166d1a6d...afb8be, treat the machine as compromised. Next, check proxy and DNS logs for the hosts in the indicator list. Search endpoint logs for the three security product names above, because the loader reads that process list.

Do not rely on the signature check alone. Run this command to read the signer.

Get-AuthenticodeSignature .\CyberLink_Promeo_Downloader.exe | Format-List

The bad file will show CyberLink Corp. as the signer. Microsoft has since disallowed that certificate, so Windows can flag it.

What to do now

  1. Hash every copy of CyberLink_Promeo_Downloader.exe on your fleet and compare it with the published SHA-256.
  2. Isolate any machine that ran the bad file.
  3. Reset credentials and tokens that were present on that machine.
  4. Check device timelines for lateral movement, as Microsoft advises.
  5. Enable Microsoft Defender Antivirus cloud protection and network protection if you use Defender.
  6. Turn on the attack surface reduction rule that blocks executables that do not meet a prevalence, age, or trusted list criterion.

Vigilance compares the installer you trust with the new one. In this case the new executable gained download, decrypt, and load behavior that the clean signed downloader did not have. That change shows in the file even when the signature is valid.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old CyberLink-prev --new CyberLink-current
files scanned: 71

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    CyberLink_Promeo_Downloader.exe
           It now downloads from the internet, runs other programs and runs a hidden, encoded command. It did not before.

Frequently asked questions

What was the CyberLink supply chain attack?

Attackers put a modified CyberLink Promeo installer on CyberLink's update servers. It had a valid CyberLink signature. Microsoft saw it on over 100 devices in Japan, Taiwan, Canada, and the United States and linked it to Diamond Sleet.

How does the modified CyberLink installer work?

It checks the local date and time, stops if it finds CrowdStrike, FireEye, or Tanium processes, then downloads a fake PNG file. It decrypts the payload from that file and runs it in memory.

Sources

  1. microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/
  2. bleepingcomputer.com/news/security/microsoft-lazarus-hackers-breach-cyberlink-in-supply-chain-attack/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free