疑似3CX供应链攻击组织相关联的Linux样本分析
2023-04-24 • Sangfor • Analysis of Linux samples associated with suspected 3CX supply chain attack organization •
Sangfor analyzes a Linux sample it says shares code traits with malware discussed in the 3CX supply-chain investigation and Lazarus Operation DreamJob reporting. The source cites Mandiant’s assessment that UNC4736 was linked to a Northeast Asian state and ESET’s reporting on SimpleTea, a Linux backdoor distributed through fake job lures, while presenting the captured sample as a possible Linux component from the same broader activity set. The malware reads or creates an encrypted configuration file at /etc/apdl.cf using XOR 0x5e, stores C2 data there, and parses remote commands after connecting to attacker infrastructure. The report lists C2-style URLs including rgedist.com/sfxl.php and journalide.org/djour.php and warns that the 3CX incident spanned Windows, macOS, and Linux tooling.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | rgedist.com | 2023-04-24 | 2024-09-18 |
| DOMAIN | journalide.org | 2023-03-29 | 2023-05-09 |
| URL | https://rgedist.com/sfxl.php | 2023-04-24 | 2023-04-24 |
| URL | https://journalide.org/djour.php | 2023-04-20 | 2023-04-24 |