Ironing out (the macOS details) of a Smooth Operator
2023-03-29 • Objective-see •
Objective-See analyzed the macOS side of the 3CX SmoothOperator supply-chain incident after other reports noted possible macOS trojanization and public commentary attributed the broader activity to Lazarus Group. The source identified a malicious libffmpeg.dylib buried inside the signed and Apple-notarized 3CX Desktop App bundle, with the x86_64 slice showing XOR loops, timing checks, dynamic API resolution, string obfuscation, and a pthread-created execution path. The analysis used a custom dlopen loader and LLDB to debug the dynamic library, focusing on the infected Intel build while noting the Arm version did not appear infected. The malware attempted to reach pbxsources.com, which was already offline during analysis, limiting observation of later-stage behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | visualstudiofactory.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | akamaitechcloudservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msedgepackageinfo.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azureonlinestorage.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officestoragebox.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxphonenetwork.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | sourceslabs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officeaddons.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | glcloudservice.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxcloudeservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azuredeploystore.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxsources.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageboxes.com | 2023-03-29 | 2024-09-09 |
| HASH | 769383fc65d1386dd141c960c997011… | 2023-03-29 | 2023-06-29 |
| HASH | 3dc840d32ce86cebf657b17cef62814… | 2023-03-29 | 2023-06-29 |
| URL | https://pbxsources.com/queue | 2023-03-29 | 2023-06-29 |
| DOMAIN | acharryblogs.com | 2023-03-29 | 2023-03-29 |
| DOMAIN | wiolnk.cn | 2023-03-29 | 2023-03-29 |