3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible
2023-04-20 • Mandiant •
https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise
Mandiant found that the 3CX Desktop App supply-chain compromise began with an earlier compromised X_TRADER installer from Trading Technologies, making it a cascading software supply-chain attack. The X_TRADER package deployed VEILEDSIGNAL through DLL side-loading, SIGFLIP, and DAVESHELL, while the later 3CX compromise distributed SUDDENICON and ICONICSTEALER and involved Windows and macOS build environment access. Mandiant tracks the 3CX activity as UNC4736, a suspected North Korean nexus cluster, and assesses with moderate confidence that it relates to financially motivated North Korean AppleJeus activity. Supporting evidence includes overlap with prior Google TAG reporting on Trading Technologies compromise, POOLRAT infrastructure using journalide[.]org, older POOLRAT links to CISA-reported AppleJeus activity, and weaker DNS overlap with suspected APT43 clusters.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 451c23709ecd5a8461ad060f6346930c | 2023-04-20 | 2023-10-05 |
| HASH | c6441c961dcad0fe127514a918eaabd4 | 2023-04-20 | 2023-04-20 |
| HASH | 19dbffec4e359a198daf4ffca1ab9165 | 2023-04-20 | 2023-04-20 |
| HASH | ef4ab22e565684424b4142b1294f1f4d | 2023-04-20 | 2023-04-20 |