LambLoad is a weaponized downloader/loader tracked by Microsoft, consisting of malicious code added to a legitimate CyberLink application installer in a supply chain compromise attributed with high confidence to the North Korea-based threat actor Diamond Sleet (formerly ZINC). The trojanized installer was hosted on CyberLink’s legitimate update infrastructure and signed with a valid CyberLink code-signing certificate. Microsoft observed suspicious activity associated with the modified installer as early as 2023-10-20, and the campaign affected more than 100 devices in multiple countries including Japan, Taiwan, Canada, and the United States.
Behaviorally, LambLoad conditionally executes its malicious logic only within a preconfigured time window and checks for processes associated with security products including CrowdStrike (csfalconservice.exe), FireEye (xagt.exe), and Tanium (taniumclient.exe). If those criteria are not met, it continues running the legitimate CyberLink software and abandons further malicious execution. If criteria are met, it downloads a second-stage payload disguised as a PNG using the User-Agent string "Microsoft Internet Explorer." The fake PNG contains an embedded payload behind a false outer PNG header; LambLoad carves, decrypts, and launches the payload in memory.
Observed stage-2 staging URLs include hxxps://i.stack.imgur[.]com/NDTUM.png, hxxps://www.webville[.]net/images/CL202966126.png, and hxxps://cldownloader.github[.]io/logo.png. The in-memory second stage attempts to contact callback URLs on compromised legitimate domains including hxxps://mantis.jancom[.]pl/bluemantis/image/addon/addin.php and hxxps://zeduzeventos.busqueabuse[.]com/wp-admin/js/widgets/sub/wids.php. Microsoft stated the second-stage payload communicates with infrastructure previously compromised by Diamond Sleet. At the time of reporting, Microsoft had not identified hands-on-keyboard activity after compromise via this malware.
Known indicators directly mentioned in the content include primary LambLoad sample SHA-256 166d1a6ddcde4e859a89c2c825cd3c8c953a86bfa92b343de7e5bfbfb5afb8be, crypted PNG payload SHA-256 089573b3a1167f387dcdad5e014a5132e998b2c89bff29bcf8b06dd497d4e63d, and decrypted second-stage PE SHA-256 915c2495e03ff7408f11a2a197f23344004c533ff87db4b807cc937f80c217a1. The abused certificate details were issuer "DigiCert SHA2 Assured ID Code Signing CA," signer "CyberLink Corp.," SignerHash 8aa3877ab68ba56dabc2f2802e813dc36678aef4, and serial number 0a08d3601636378f0a7d64fd09e4a13b. Microsoft Defender Antivirus detects the malware as Trojan:Win32/LambLoad, including variants Trojan:Win32/LambLoad.A, .B, .C and Trojan:Win64/LambLoad.D and .E. Microsoft also noted Diamond Sleet has used trojanized open-source and proprietary software to target IT, defense, and media organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LambLoad is a malware loader distributed via a supply chain compromise of a legitimate CyberLink installer, attributed to the North Korean threat actor Diamond Sleet (ZINC). It is used to deliver additional malicious payloads to compromised systems.
Trojanized, code-signed CyberLink installer modified to act as a downloader/loader: performs time-window execution checks, evades certain EDRs by process checks, downloads a fake-PNG second stage from staging URLs, carves/decrypts an embedded payload, and executes it in-memory to communicate with attacker-controlled (compromised) infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.