Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack
2023-04-03 • Kaspersky •
https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/
Kaspersky investigated whether the 3CX supply-chain compromise led only to an infostealer or also to follow-on implants, and found Gopuram backdoor deployments tied to infected 3CXDesktopApp processes. The report says Gopuram infections rose in March 2023 and were specifically observed against cryptocurrency companies, with persistence through malicious DLLs such as wlbsctrl.dll and encrypted shellcode stored under the Windows TxR path. Gopuram’s main module, guard64.dll, connects to C2 and supports file-system interaction, process creation, registry and service manipulation, timestomping, injection, driver-loading support, updates, and partial net-command functionality. Kaspersky attributes the 3CX campaign to Lazarus with medium to high confidence based on Gopuram’s prior coexistence with AppleJeus at a Southeast Asian cryptocurrency company, Lazarus-aligned targeting of cryptocurrency firms, and infrastructure overlap involving wirexpro[.]com.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f684e10ff1ffcdd32c62e73a11382896 | 2023-04-03 | 2023-04-03 |
| HASH | 9f85a07d4b4abff82ca18d990f062a84 | 2023-04-03 | 2023-04-03 |
| HASH | ec3f99dd7d9dbce8d704d407b086e84f | 2023-04-03 | 2023-04-03 |
| HASH | 933508a9832da1150fcfdbc1ca9bc84c | 2023-04-03 | 2023-04-03 |
| HASH | 96d3bbf4d2cf6bc452b53c67b3f2516a | 2023-04-03 | 2023-04-03 |
| DOMAIN | wirexpro.com | 2022-12-01 | 2023-04-03 |
| DOMAIN | oilycargo.com | 2022-12-01 | 2023-04-03 |