Shares tags: Youtube, SupplyChain, 3CXDesktopApp • Same author: struppigel • Published within a week
3CX SmoothOperator Authenticode Abuse
2023-04-05 • struppigel •
This follow-up analysis explains how the 3CX SmoothOperator malware abused Authenticode without stealing Microsoft certificates. The trojanized ffmpeg.dll extracted malicious data from d3dcompiler_47.dll, whose certificate remained valid because the attackers placed data in parts of the certificate structure excluded from the Authenticode hash. The video points to SigFlip style abuse, certificate padding and unauthenticated attribute checks, and tools such as AnalyzePESig for detecting bytes appended inside or after the signature area.
Related Reports
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
2023-04-21 •
50% Match
X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe
Symantec
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month