CrowdStrike Prevents 3CXDesktopApp Intrusion Campaign
2023-03-29 • Crowd Strike •
CrowdStrike observed malicious activity from the legitimate signed 3CXDesktopApp softphone binary on Windows and macOS, including beaconing, second-stage payload deployment, and limited hands-on-keyboard activity. CrowdStrike Intelligence assessed suspected nation-state involvement by LABYRINTH CHOLLIMA, tying the intrusion campaign to DPRK-focused tracking without providing additional attribution detail in the excerpt. The activity used 3CXDesktopApp abuse to reach actor-controlled domains such as akamaicontainer[.]com, azuredeploystore[.]com, journalide[.]org, msedgepackageinfo[.]com, pbxsources[.]com, and visualstudiofactory[.]com. The report matters because a trusted commercial application became the initial source of malicious telemetry, requiring defenders to hunt for 3CXDesktopApp presence and historical DNS activity across endpoint environments.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e6bbc33815b9f20b0cf832d7401dd89… | 2023-03-29 | 2024-12-27 |
| DOMAIN | visualstudiofactory.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | akamaitechcloudservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msedgepackageinfo.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageazure.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azureonlinestorage.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | zacharryblogs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officestoragebox.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxphonenetwork.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | sourceslabs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officeaddons.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | glcloudservice.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxcloudeservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azuredeploystore.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxsources.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageboxes.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | journalide.org | 2023-03-29 | 2023-05-09 |
| HASH | 5407cda7d3a75e7b1e030b1f33337a5… | 2023-03-29 | 2023-04-28 |
| HASH | dde03348075512796241389dfea5560… | 2023-03-29 | 2023-04-28 |
| HASH | fad482ded2e25ce9e1dd3d3ecc3227a… | 2023-03-29 | 2023-04-28 |
| HASH | 59e1edf4d82fae4978e97512b0331b7… | 2023-03-29 | 2023-04-28 |
| HASH | aa124a4b4df12b34e74ee7f6c683b2e… | 2023-03-29 | 2023-04-28 |
| DOMAIN | qwepoi123098.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | akamaicontainer.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | dunamistrd.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | azureonlinecloud.com | 2023-03-29 | 2023-04-28 |
| HASH | 92005051ae314d61074ed94a52e76b1… | 2023-03-29 | 2023-03-31 |
| HASH | b86c695822013483fa4e2dfdf712c5e… | 2023-03-29 | 2023-03-31 |