3CXのソフトウエア改ざんによるサプライチェーン攻撃についてまとめてみた
2023-04-03 • piyokango • A summary of supply chain attacks caused by 3CX software tampering •
Piyolog summarizes the March 2023 3CX supply-chain compromise in which tampered Windows and macOS 3CX client installers were distributed and could infect users with malware capable of stealing browser-stored information. The source notes that 3CX products were used globally across many sectors, including automotive, MSP, and manufacturing, and cites CrowdStrike’s high-confidence assessment that LABYRINTH CHOLLIMA, a North Korea-linked threat actor, was involved, while Volexity and others also tied the activity to Lazarus. The article lists affected versions, CVE-2023-29059, mitigation steps such as uninstalling affected desktop clients and using the PWA version, and monitoring guidance for proxy, endpoint, and network logs. It also provides representative attacker infrastructure such as akamaitechcloudservices[.]com, azureonlinestorage[.]com, glcloudservice[.]com, msedgepackageinfo[.]com, officestoragebox[.]com, and pbxsources[.]com, while warning that some listed domains may not be attacker-controlled.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e6bbc33815b9f20b0cf832d7401dd89… | 2023-03-29 | 2024-12-27 |
| DOMAIN | visualstudiofactory.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | akamaitechcloudservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msedgepackageinfo.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageazure.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azureonlinestorage.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | zacharryblogs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officestoragebox.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxphonenetwork.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | sourceslabs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officeaddons.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | glcloudservice.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxcloudeservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azuredeploystore.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxsources.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageboxes.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | journalide.org | 2023-03-29 | 2023-05-09 |
| HASH | 5407cda7d3a75e7b1e030b1f33337a5… | 2023-03-29 | 2023-04-28 |
| HASH | 59e1edf4d82fae4978e97512b0331b7… | 2023-03-29 | 2023-04-28 |
| HASH | aa124a4b4df12b34e74ee7f6c683b2e… | 2023-03-29 | 2023-04-28 |
| DOMAIN | qwepoi123098.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | akamaicontainer.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | dunamistrd.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | azureonlinecloud.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | msedgeupdate.net | 2023-03-30 | 2023-04-03 |