Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
A Comprehensive Analysis of the 3CX Attack
2023-03-31 • Cyble •
https://blog.cyble.com/2023/03/31/a-comprehensive-analysis-of-the-3cx-attack/
To obtain distinct C&C URLs, the malware randomly selects an ICO file from a GitHub repository. This malware can gather system data and take control of data and login credentials stored in user profiles on various web browsers, including Chrome, Edge, Brave, and Firefox. This attack has been attributed to North Korean Threat Actors (TAs). The attack involves a Trojanized version of the 3CX, a Voice Over Internet Protocol (VOIP) desktop client, which has been digitally signed.
Related Reports
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
2023-04-21 •
60% Match
X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe
Symantec
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Published within a month