3CX Breach Was a Double Supply Chain Compromise

2023-04-20 Krebsonsecurity

https://krebsonsecurity.com/2023/04/3cx-breach-was-a-double-supply-chain-compromise/

Thumbnail for 3CX Breach Was a Double Supply Chain Compromise

Krebs reported that the 3CX compromise was a nested supply-chain incident: a 3CX employee first installed a trojanized X_TRADER package, after which attackers used the employee's credentials to access 3CX and compromise Windows and macOS build environments. Mandiant attributed the operation to Lazarus, and the compromised 3CX applications later pulled encrypted icon files from GitHub to locate command infrastructure and deliver ICONICSTEALER. The article also connects the activity to Lazarus social-engineering operations using fake LinkedIn recruiter profiles and job-offer lures, including ESET findings on Linux-targeting malware disguised as an HSBC employment document.

Related Reports

2023-04-20 • 60% Match
#YARA #SupplyChain #3CXDesktopApp #SmoothOperator #UNC4736 #X_Trader #UNC4469 #UNC3782 #T1082 #T1140 #T1070.004 #T1071.001 #T1195.002 #T1112 #T1083 #T1497 #T1036 #T1027 #T1071 #T1195 #T1497.001 #T1105 #T1055 #T1620 #T1574.002 #T1622 #T1190 #T1588 #T1574 #T1573.002 #T1614 #T1573 #T1608 #T1070 #T1614.001 #T1071.004 #T1012 #T1588.004 #T1565.001 #T1036.001 #T1070.001 #T1608.003 #T1565
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a week
« Back