3CX users under DLL-sideloading attack: What you need to know
2023-03-29 • Sophos •
https://news.sophos.com/en-us/2023/03/29/3cx-dll-sideloading-attack/
Sophos X-Ops described a developing 3CX Desktop application supply-chain attack, possibly involving a nation-state-related group, that abused signed Windows softphone packages to communicate with multiple C2 servers. The attack used a DLL sideloading chain with a clean 3CXDesktopApp.exe loader, a d3dcompiler_47.dll containing an appended encrypted payload, and a trojanized ffmpeg.dll that retrieved encoded .ico payloads. Sophos MDR observed malicious activity from customer 3CXDesktopApp installations on March 29, 2023, and noted that public file storage had hosted encoded malware since December 8, 2022. The source provides hunting guidance for known domains such as akamaicontainer.com, azuredeploystore.com, journalide.org, pbxsources.com, and raw.githubusercontent.com/IconStorages/images paths.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | visualstudiofactory.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | akamaitechcloudservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msedgepackageinfo.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageazure.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azureonlinestorage.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | zacharryblogs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officestoragebox.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxphonenetwork.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | sourceslabs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officeaddons.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | glcloudservice.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxcloudeservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azuredeploystore.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxsources.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageboxes.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | journalide.org | 2023-03-29 | 2023-05-09 |
| DOMAIN | qwepoi123098.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | akamaicontainer.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | dunamistrd.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | azureonlinecloud.com | 2023-03-29 | 2023-04-28 |