Mac-ing sense of the 3CX supply chain attack: analysis of the macOS payloads

2023-10-05 Objective-see

https://www.virusbulletin.com/conference/vb2023/abstracts/mac-ing-sense-3cx-supply-chain-attack-analysis-macos-payloads/

Attachments

Mac-ing-sense-of-the-3CX-supply-chain-attack-analysis-of-the-macOS_9ZmzAbw.pdf (1 MB)

Thumbnail for Mac-ing sense of the 3CX supply chain attack: analysis of the macOS payloads

The 3CX compromise is presented as a chained supply-chain attack in which a trojanized Trading Technologies X_TRADER installer first infected a 3CX employee’s personal machine. Mandiant attributed the activity to a suspected North Korean actor tracked as UNC4736 and found that the attackers harvested credentials, moved laterally through 3CX, and compromised both Windows and macOS build environments. The macOS build server was reportedly infected with the POOLRAT backdoor using LaunchDaemons for persistence before malicious components were slipstreamed into signed and notarized 3CX macOS installers. Objective-See’s analysis focuses on the macOS implant, the malicious library delivered through the trojanized installer, and a self-deleting second-stage payload, while also noting POOLRAT detection artifacts including YARA strings and MD5 references. The case matters because it shows how one trusted software supply chain was used to compromise another, extending impact to enterprise macOS users.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6c121f2b2efa6592c2c22b29218157e… 2023-06-29 2024-12-27
HASH a64fa9f1c76457ecc58402142a8728c… 2023-03-30 2024-12-27
DOMAIN visualstudiofactory.com 2023-03-29 2024-09-09
DOMAIN akamaitechcloudservices.com 2023-03-29 2024-09-09
DOMAIN msedgepackageinfo.com 2023-03-29 2024-09-09
DOMAIN azureonlinestorage.com 2023-03-29 2024-09-09
DOMAIN zacharryblogs.com 2023-03-29 2024-09-09
DOMAIN officestoragebox.com 2023-03-29 2024-09-09
DOMAIN pbxphonenetwork.com 2023-03-29 2024-09-09
DOMAIN sourceslabs.com 2023-03-29 2024-09-09
DOMAIN officeaddons.com 2023-03-29 2024-09-09
DOMAIN glcloudservice.com 2023-03-29 2024-09-09
DOMAIN pbxcloudeservices.com 2023-03-29 2024-09-09
DOMAIN azuredeploystore.com 2023-03-29 2024-09-09
DOMAIN pbxsources.com 2023-03-29 2024-09-09
DOMAIN msstorageboxes.com 2023-03-29 2024-09-09
DOMAIN globalkeystroke.com 2021-02-18 2024-09-09
DOMAIN airbseeker.com 2021-02-18 2024-09-09
URL https://sbmsa.wiki/blog/_insert 2023-04-01 2024-01-01
DOMAIN sbmsa.wiki 2023-04-01 2024-01-01
YARA XProtect_MACOS_c723519 2023-10-05 2023-10-05
YARA MTI_Hunting_POOLRAT 2023-10-05 2023-10-05
DOMAIN o.cn 2023-10-05 2023-10-05
HASH 5555494424668e99d3173e03a74c868… 2023-08-10 2023-10-05
URL https://globalkeystroke.com/poc… 2023-08-10 2023-10-05
URL https://airbseeker.com/rediret.… 2023-08-10 2023-10-05
URL https://www.woodmate.it/adminis… 2023-08-10 2023-10-05
URL https://akamaitechcloudservices… 2023-06-29 2023-10-05
HASH 451c23709ecd5a8461ad060f6346930c 2023-04-20 2023-10-05
HASH d9d19abffc2c7dac11a16745f4aea44f 2023-04-11 2023-10-05
HASH 55554944839216049d683075bc3f5a8… 2023-04-01 2023-10-05

Related Reports

« Back