3CX users under DLL-sideloading attack: What you need to know

2023-03-29 Sophos

https://news.sophos.com/en-us/2023/03/29/3cx-dll-sideloading-attack/

Thumbnail for 3CX users under DLL-sideloading attack: What you need to know

Sophos X-Ops described a developing 3CX Desktop application supply-chain attack, possibly involving a nation-state-related group, that abused signed Windows softphone packages to communicate with multiple C2 servers. The attack used a DLL sideloading chain with a clean 3CXDesktopApp.exe loader, a d3dcompiler_47.dll containing an appended encrypted payload, and a trojanized ffmpeg.dll that retrieved encoded .ico payloads. Sophos MDR observed malicious activity from customer 3CXDesktopApp installations on March 29, 2023, and noted that public file storage had hosted encoded malware since December 8, 2022. The source provides hunting guidance for known domains such as akamaicontainer.com, azuredeploystore.com, journalide.org, pbxsources.com, and raw.githubusercontent.com/IconStorages/images paths.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN visualstudiofactory.com 2023-03-29 2024-09-09
DOMAIN akamaitechcloudservices.com 2023-03-29 2024-09-09
DOMAIN msedgepackageinfo.com 2023-03-29 2024-09-09
DOMAIN msstorageazure.com 2023-03-29 2024-09-09
DOMAIN azureonlinestorage.com 2023-03-29 2024-09-09
DOMAIN zacharryblogs.com 2023-03-29 2024-09-09
DOMAIN officestoragebox.com 2023-03-29 2024-09-09
DOMAIN pbxphonenetwork.com 2023-03-29 2024-09-09
DOMAIN sourceslabs.com 2023-03-29 2024-09-09
DOMAIN officeaddons.com 2023-03-29 2024-09-09
DOMAIN glcloudservice.com 2023-03-29 2024-09-09
DOMAIN pbxcloudeservices.com 2023-03-29 2024-09-09
DOMAIN azuredeploystore.com 2023-03-29 2024-09-09
DOMAIN pbxsources.com 2023-03-29 2024-09-09
DOMAIN msstorageboxes.com 2023-03-29 2024-09-09
DOMAIN journalide.org 2023-03-29 2023-05-09
DOMAIN qwepoi123098.com 2023-03-29 2023-04-28
DOMAIN akamaicontainer.com 2023-03-29 2023-04-28
DOMAIN dunamistrd.com 2023-03-29 2023-04-28
DOMAIN azureonlinecloud.com 2023-03-29 2023-04-28

Related Reports

« Back