疑似3CX供应链攻击组织相关联的Linux样本分析

2023-04-24 Sangfor Analysis of Linux samples associated with suspected 3CX supply chain attack organization

https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247518550&idx=1&sn=c8880d309c2adae333fa9388fd48ae2a&chksm=ce460246f9318b5010682c3d1dc3dab6ec82b29dd7fcf4b85e377f230d4e78998910281b8459&scene=178&cur_album_id=2867627575890837505#rd

Thumbnail for 疑似3CX供应链攻击组织相关联的Linux样本分析

Sangfor analyzes a Linux sample it says shares code traits with malware discussed in the 3CX supply-chain investigation and Lazarus Operation DreamJob reporting. The source cites Mandiant’s assessment that UNC4736 was linked to a Northeast Asian state and ESET’s reporting on SimpleTea, a Linux backdoor distributed through fake job lures, while presenting the captured sample as a possible Linux component from the same broader activity set. The malware reads or creates an encrypted configuration file at /etc/apdl.cf using XOR 0x5e, stores C2 data there, and parses remote commands after connecting to attacker infrastructure. The report lists C2-style URLs including rgedist.com/sfxl.php and journalide.org/djour.php and warns that the 3CX incident spanned Windows, macOS, and Linux tooling.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN rgedist.com 2023-04-24 2024-09-18
DOMAIN journalide.org 2023-03-29 2023-05-09
URL https://rgedist.com/sfxl.php 2023-04-24 2023-04-24
URL https://journalide.org/djour.php 2023-04-20 2023-04-24

Related Reports

« Back