3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible

2023-04-20 Mandiant

https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise

Thumbnail for 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible

Mandiant found that the 3CX Desktop App supply-chain compromise began with an earlier compromised X_TRADER installer from Trading Technologies, making it a cascading software supply-chain attack. The X_TRADER package deployed VEILEDSIGNAL through DLL side-loading, SIGFLIP, and DAVESHELL, while the later 3CX compromise distributed SUDDENICON and ICONICSTEALER and involved Windows and macOS build environment access. Mandiant tracks the 3CX activity as UNC4736, a suspected North Korean nexus cluster, and assesses with moderate confidence that it relates to financially motivated North Korean AppleJeus activity. Supporting evidence includes overlap with prior Google TAG reporting on Trading Technologies compromise, POOLRAT infrastructure using journalide[.]org, older POOLRAT links to CISA-reported AppleJeus activity, and weaker DNS overlap with suspected APT43 clusters.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 451c23709ecd5a8461ad060f6346930c 2023-04-20 2023-10-05
HASH c6441c961dcad0fe127514a918eaabd4 2023-04-20 2023-04-20
HASH 19dbffec4e359a198daf4ffca1ab9165 2023-04-20 2023-04-20
HASH ef4ab22e565684424b4142b1294f1f4d 2023-04-20 2023-04-20

Related Actors

Related Reports

« Back