Lazarus Operation DreamJob – Ataque a la cadena de suministro de 3CX

2023-05-09 Ecu CERT

https://www.ecucert.gob.ec/wp-content/uploads/2023/05/20-Linux.pdf

Attachments

20-Linux.pdf (1 MB)

Thumbnail for Lazarus Operation DreamJob – Ataque a la cadena de suministro de 3CX

Lazarus Operation DreamJob activity used a fake HSBC job-offer lure to deliver a native 64-bit Linux ELF downloader, expanding the campaign beyond earlier Windows and macOS targeting. The infection chain starts with a ZIP containing a deceptive file name that appears to be a PDF, opens a decoy document with the system PDF viewer, and uses OdicLoader to fetch the SimplexTea Linux backdoor from OpenDrive. Persistence is established by modifying ~/.bash_profile so the downloaded backdoor runs with Bash while suppressing output. The excerpt links SimplexTea to Lazarus tooling similarities and notes that the Linux payload strengthens the case connecting Lazarus to the 3CX supply-chain compromise, where trojanized Windows and macOS 3CX applications enabled arbitrary payload delivery.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cc307cfb401d1ae616445e78b610ab7… 2023-04-20 2025-12-17
IPv4 23.254.211.230 2023-04-20 2025-12-17
IPv4 172.93.201.88 2023-04-20 2025-11-09
HASH 492a643bd1efdaca4ca125ade1b606e… 2023-04-20 2024-12-27
HASH ce6b4f2a94f0f0f93850f3a2723d1627 2023-05-09 2023-05-09
HASH 988ec0c1a4e6a056b92da307c6f68b17 2023-05-09 2023-05-09
HASH ab530f284a04fcfc070e237fd2a52e04 2023-05-09 2023-05-09
HASH 3a63477a078ce10e53dfb5639e35d74… 2023-04-20 2023-05-09
HASH 9d8bade2030c93d0a010aa57b90915e… 2023-04-20 2023-05-09
HASH 3cf7232e5185109321921046d039cf10 2023-04-20 2023-05-09
HASH aac5a52b939f3fe792726a13ff7a1747 2023-04-20 2023-05-09
HASH 0ca1723afe261cd85b05c9ef424fc50… 2023-04-20 2023-05-09
HASH f638e5a20114019ad066dd0e856f97f… 2023-04-20 2023-05-09
HASH f6760fb1f8b019af2304ea6410001b6… 2023-04-20 2023-05-09
HASH fc41cb8425b6432af8403959bb59430d 2023-04-20 2023-05-09
IPv4 38.108.185.79 2023-04-20 2023-05-09
IPv4 38.108.185.115 2023-04-20 2023-05-09
DOMAIN journalide.org 2023-03-29 2023-05-09

Related Reports

2023-04-20 • 29% Match
#YARA #SupplyChain #3CXDesktopApp #SmoothOperator #UNC4736 #X_Trader #UNC4469 #UNC3782 #T1082 #T1140 #T1070.004 #T1071.001 #T1195.002 #T1112 #T1083 #T1497 #T1036 #T1027 #T1071 #T1195 #T1497.001 #T1105 #T1055 #T1620 #T1574.002 #T1622 #T1190 #T1588 #T1574 #T1573.002 #T1614 #T1573 #T1608 #T1070 #T1614.001 #T1071.004 #T1012 #T1588.004 #T1565.001 #T1036.001 #T1070.001 #T1608.003 #T1565
Shares tags: SmoothOperator, T1140, T1070.004 • Published within a month
« Back