Security researchers reported multiple campaigns using trojanized versions of PuTTY and other legitimate tools to compromise high-value users, including administrators, engineers, and technical support staff. LevelBlue said a recent malvertising operation pushed fake PuTTY installers through Bing sponsored ads and typosquatted domains such as puttyy[.]org and puttysystems[.]com, with a signed malicious executable creating scheduled-task persistence, dropping twain_96.dll and green.dll, and communicating with infrastructure linked to Broomstick/Oyster malware. In affected environments, the intrusions progressed to hands-on-keyboard activity, reconnaissance via cmd.exe, and Kerberoasting using an in-memory script derived from PowerSploit’s Invoke-Kerberoast to obtain RC4-HMAC Kerberos service tickets for offline cracking.
Microsoft previously described a related tradecraft pattern in which North Korean state-backed ZINC—now tracked as Diamond Sleet—used social engineering on LinkedIn and WhatsApp to deliver weaponized open-source software, including PuTTY, KiTTY, TightVNC Viewer, Sumatra PDF Reader, and muPDF, to targets in media, defense, aerospace, and IT services across several countries. That activity deployed the ZetaNile malware family using DLL search-order hijacking, staged payloads, persistence, lateral movement, and data exfiltration, while separate analysis of Lazarus-linked BLINDINGCAN showed the group’s broader capability set for encrypted command-and-control, remote command execution, file transfer, and system discovery. Together, the reporting shows attackers repeatedly abusing trusted admin and open-source tools as malware delivery vehicles to gain persistence, steal credentials, and expand access inside victim networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Microsoft publicly attributed the campaign to ZINC, now tracked as Diamond Sleet, and described the ZetaNile/BLINDINGCAN malware family, lateral movement, exfiltration, and the use of weaponized open-source software.
Microsoft said the actor began using a trojanized TightVNC Viewer in September 2022, delivering it alongside a weaponized SSH utility over WhatsApp.
Microsoft observed the campaign from late April to mid-September 2022 and said ZINC successfully compromised numerous organizations in media, defense and aerospace, and IT services using weaponized tools including PuTTY, KiTTY, TightVNC Viewer, Sumatra PDF Reader, and muPDF/Subliminal Recording installer.
Microsoft said the North Korean threat actor ZINC began the campaign in June 2022 by contacting targets on LinkedIn to build trust before moving conversations to WhatsApp for malware delivery.
Following the incidents, LevelBlue conducted threat hunting across customer environments for campaign indicators and created new custom SentinelOne detection rules based on the observed IOCs and TTPs.
LevelBlue isolated affected endpoints using SentinelOne, advised disabling the impacted user account, and recommended resetting credentials for SPN accounts observed in Kerberos ticket requests.
LevelBlue observed hands-on-keyboard activity via cmd.exe, reconnaissance commands such as nltest and net group, and execution of an in-memory Kerberoasting script derived from PowerSploit's Invoke-Kerberoast to request RC4-HMAC-encrypted service tickets for offline cracking.
In the investigated incident, the fake PuTTY executable signed by "NEW VISION MARKETING LLC" created a scheduled task named "Security Updater," dropped twain_96.dll and green.dll, and communicated with infrastructure consistent with Broomstick/Oyster malware.
LevelBlue documented several incidents in which privileged users downloaded fake PuTTY installers delivered through malicious Bing sponsored ads and typosquatted PuTTY-themed domains.
LinkedIn Threat Prevention and Defense detected ZINC creating fraudulent recruiter profiles impersonating technology, defense, and media entertainment companies and terminated the associated accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.