3CX Supply Chain Attack

2023-03-30 Open Analysis

https://research.openanalysis.net/3cx/northkorea/apt/triage/2023/03/30/3cx-malware.html

Thumbnail for 3CX Supply Chain Attack

OpenAnalysis examined the 3CX supply-chain compromise by unpacking the signed 3CXDesktopApp-18.12.416.msi and tracing how the backdoored client delivered malware. The analysis found that ffmpeg.dll locates d3dcompiler_47.dll, searches for repeated FEEDFACE markers, decrypts appended data with RC4, and executes shellcode plus an embedded PE payload in memory. The malware creates a manifest file to enforce a delayed execution window, reads the MachineGuid value, and builds requests to the IconStorages GitHub repository for numbered icon files. Appended data in the icons is base64-decoded and decrypted to reveal stage-two C2 URLs such as pbxsources[.]com/exchange, although the source did not recover stage three.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN pbxsources.com 2023-03-29 2024-09-09
URL https://pbxsources.com/exchange 2023-03-30 2023-04-05
HASH b56279136d816a11cf4db9fc1b249da… 2023-03-30 2023-03-30

Related Reports

« Back