Mac-ing sense of the 3CX supply chain attack: analysis of the macOS payloads
2023-10-05 • Objective-see •
Attachments
The 3CX compromise is presented as a chained supply-chain attack in which a trojanized Trading Technologies X_TRADER installer first infected a 3CX employee’s personal machine. Mandiant attributed the activity to a suspected North Korean actor tracked as UNC4736 and found that the attackers harvested credentials, moved laterally through 3CX, and compromised both Windows and macOS build environments. The macOS build server was reportedly infected with the POOLRAT backdoor using LaunchDaemons for persistence before malicious components were slipstreamed into signed and notarized 3CX macOS installers. Objective-See’s analysis focuses on the macOS implant, the malicious library delivered through the trojanized installer, and a self-deleting second-stage payload, while also noting POOLRAT detection artifacts including YARA strings and MD5 references. The case matters because it shows how one trusted software supply chain was used to compromise another, extending impact to enterprise macOS users.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6c121f2b2efa6592c2c22b29218157e… | 2023-06-29 | 2024-12-27 |
| HASH | a64fa9f1c76457ecc58402142a8728c… | 2023-03-30 | 2024-12-27 |
| DOMAIN | visualstudiofactory.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | akamaitechcloudservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msedgepackageinfo.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azureonlinestorage.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | zacharryblogs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officestoragebox.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxphonenetwork.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | sourceslabs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officeaddons.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | glcloudservice.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxcloudeservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azuredeploystore.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxsources.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageboxes.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | globalkeystroke.com | 2021-02-18 | 2024-09-09 |
| DOMAIN | airbseeker.com | 2021-02-18 | 2024-09-09 |
| URL | https://sbmsa.wiki/blog/_insert | 2023-04-01 | 2024-01-01 |
| DOMAIN | sbmsa.wiki | 2023-04-01 | 2024-01-01 |
| YARA | XProtect_MACOS_c723519 | 2023-10-05 | 2023-10-05 |
| YARA | MTI_Hunting_POOLRAT | 2023-10-05 | 2023-10-05 |
| DOMAIN | o.cn | 2023-10-05 | 2023-10-05 |
| HASH | 5555494424668e99d3173e03a74c868… | 2023-08-10 | 2023-10-05 |
| URL | https://globalkeystroke.com/poc… | 2023-08-10 | 2023-10-05 |
| URL | https://airbseeker.com/rediret.… | 2023-08-10 | 2023-10-05 |
| URL | https://www.woodmate.it/adminis… | 2023-08-10 | 2023-10-05 |
| URL | https://akamaitechcloudservices… | 2023-06-29 | 2023-10-05 |
| HASH | 451c23709ecd5a8461ad060f6346930c | 2023-04-20 | 2023-10-05 |
| HASH | d9d19abffc2c7dac11a16745f4aea44f | 2023-04-11 | 2023-10-05 |
| HASH | 55554944839216049d683075bc3f5a8… | 2023-04-01 | 2023-10-05 |