Ironing out (the macOS details) of a Smooth Operator

2023-03-29 Objective-see

https://objective-see.org/blog/blog_0x73.html

Thumbnail for Ironing out (the macOS details) of a Smooth Operator

Objective-See analyzed the macOS side of the 3CX SmoothOperator supply-chain incident after other reports noted possible macOS trojanization and public commentary attributed the broader activity to Lazarus Group. The source identified a malicious libffmpeg.dylib buried inside the signed and Apple-notarized 3CX Desktop App bundle, with the x86_64 slice showing XOR loops, timing checks, dynamic API resolution, string obfuscation, and a pthread-created execution path. The analysis used a custom dlopen loader and LLDB to debug the dynamic library, focusing on the infected Intel build while noting the Arm version did not appear infected. The malware attempted to reach pbxsources.com, which was already offline during analysis, limiting observation of later-stage behavior.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN visualstudiofactory.com 2023-03-29 2024-09-09
DOMAIN akamaitechcloudservices.com 2023-03-29 2024-09-09
DOMAIN msedgepackageinfo.com 2023-03-29 2024-09-09
DOMAIN azureonlinestorage.com 2023-03-29 2024-09-09
DOMAIN officestoragebox.com 2023-03-29 2024-09-09
DOMAIN pbxphonenetwork.com 2023-03-29 2024-09-09
DOMAIN sourceslabs.com 2023-03-29 2024-09-09
DOMAIN officeaddons.com 2023-03-29 2024-09-09
DOMAIN glcloudservice.com 2023-03-29 2024-09-09
DOMAIN pbxcloudeservices.com 2023-03-29 2024-09-09
DOMAIN azuredeploystore.com 2023-03-29 2024-09-09
DOMAIN pbxsources.com 2023-03-29 2024-09-09
DOMAIN msstorageboxes.com 2023-03-29 2024-09-09
HASH 769383fc65d1386dd141c960c997011… 2023-03-29 2023-06-29
HASH 3dc840d32ce86cebf657b17cef62814… 2023-03-29 2023-06-29
URL https://pbxsources.com/queue 2023-03-29 2023-06-29
DOMAIN acharryblogs.com 2023-03-29 2023-03-29
DOMAIN wiolnk.cn 2023-03-29 2023-03-29

Related Reports

« Back