Mandiant Security Update – Initial Intrusion Vector
2023-04-20 • 3CX •
Mandiant traced the 3CX internal compromise to an employee's personal computer after the employee installed a trojanized Trading Technologies X_TRADER package downloaded from the vendor's site. The installer carried VEILEDSIGNAL, which gave UNC4736 administrator-level access and persistence, after which the actor stole 3CX corporate credentials and accessed the company VPN two days later. Inside 3CX, the actor used Fast Reverse Proxy disguised as MsMpEng.exe for lateral movement, then compromised Windows and macOS build environments with TAXHAUL, COLDCAT, and POOLRAT. Mandiant assessed with high confidence that UNC4736 has a North Korean nexus, making the incident notable as a supply chain compromise that enabled a second software supply chain attack.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 24d5dd3006c63d0f46fb33cbc1f5763… | 2023-04-20 | 2025-12-17 |
| HASH | 6e11c02485ddd5a3798bf0f77206f2b… | 2023-04-20 | 2023-04-21 |
| HASH | 19dbffec4e359a198daf4ffca1ab9165 | 2023-04-20 | 2023-04-20 |
| HASH | 3bda9ca504146ad5558939de9fece07… | 2023-04-20 | 2023-04-20 |
| HASH | fbc50755913de619fb830fb95882e97… | 2023-04-20 | 2023-04-20 |
| HASH | 00a43d64f9b5187a1e1f922b99b09b77 | 2023-04-20 | 2023-04-20 |
| HASH | d7ba13662fbfb254acaad7ae10ad51e… | 2023-04-20 | 2023-04-20 |
| HASH | ced671856bbaef2f1878a2469fb44e9… | 2023-04-20 | 2023-04-20 |
| HASH | ef4ab22e565684424b4142b1294f1f4d | 2023-04-20 | 2023-04-20 |
| URL | https://download.tradingtechnol… | 2023-04-20 | 2023-04-20 |
| DOMAIN | download.tradingtechnologies.com | 2023-04-20 | 2023-04-20 |