Mandiant Security Update – Initial Intrusion Vector

2023-04-20 3CX

https://www.3cx.com/blog/news/mandiant-security-update2/

Thumbnail for Mandiant Security Update – Initial Intrusion Vector

Mandiant traced the 3CX internal compromise to an employee's personal computer after the employee installed a trojanized Trading Technologies X_TRADER package downloaded from the vendor's site. The installer carried VEILEDSIGNAL, which gave UNC4736 administrator-level access and persistence, after which the actor stole 3CX corporate credentials and accessed the company VPN two days later. Inside 3CX, the actor used Fast Reverse Proxy disguised as MsMpEng.exe for lateral movement, then compromised Windows and macOS build environments with TAXHAUL, COLDCAT, and POOLRAT. Mandiant assessed with high confidence that UNC4736 has a North Korean nexus, making the incident notable as a supply chain compromise that enabled a second software supply chain attack.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 24d5dd3006c63d0f46fb33cbc1f5763… 2023-04-20 2025-12-17
HASH 6e11c02485ddd5a3798bf0f77206f2b… 2023-04-20 2023-04-21
HASH 19dbffec4e359a198daf4ffca1ab9165 2023-04-20 2023-04-20
HASH 3bda9ca504146ad5558939de9fece07… 2023-04-20 2023-04-20
HASH fbc50755913de619fb830fb95882e97… 2023-04-20 2023-04-20
HASH 00a43d64f9b5187a1e1f922b99b09b77 2023-04-20 2023-04-20
HASH d7ba13662fbfb254acaad7ae10ad51e… 2023-04-20 2023-04-20
HASH ced671856bbaef2f1878a2469fb44e9… 2023-04-20 2023-04-20
HASH ef4ab22e565684424b4142b1294f1f4d 2023-04-20 2023-04-20
URL https://download.tradingtechnol… 2023-04-20 2023-04-20
DOMAIN download.tradingtechnologies.com 2023-04-20 2023-04-20

Related Actors

Related Reports

2023-04-20 • 87% Match
#YARA #SupplyChain #3CXDesktopApp #SmoothOperator #UNC4736 #X_Trader #UNC4469 #UNC3782 #T1082 #T1140 #T1070.004 #T1071.001 #T1195.002 #T1112 #T1083 #T1497 #T1036 #T1027 #T1071 #T1195 #T1497.001 #T1105 #T1055 #T1620 #T1574.002 #T1622 #T1190 #T1588 #T1574 #T1573.002 #T1614 #T1573 #T1608 #T1070 #T1614.001 #T1071.004 #T1012 #T1588.004 #T1565.001 #T1036.001 #T1070.001 #T1608.003 #T1565
Shares tags: SupplyChain, 3CXDesktopApp, SmoothOperator • Shares 2 IOCs • Published within a week
« Back