Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack

2023-04-03 Kaspersky

https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/

Thumbnail for Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack

Kaspersky investigated whether the 3CX supply-chain compromise led only to an infostealer or also to follow-on implants, and found Gopuram backdoor deployments tied to infected 3CXDesktopApp processes. The report says Gopuram infections rose in March 2023 and were specifically observed against cryptocurrency companies, with persistence through malicious DLLs such as wlbsctrl.dll and encrypted shellcode stored under the Windows TxR path. Gopuram’s main module, guard64.dll, connects to C2 and supports file-system interaction, process creation, registry and service manipulation, timestomping, injection, driver-loading support, updates, and partial net-command functionality. Kaspersky attributes the 3CX campaign to Lazarus with medium to high confidence based on Gopuram’s prior coexistence with AppleJeus at a Southeast Asian cryptocurrency company, Lazarus-aligned targeting of cryptocurrency firms, and infrastructure overlap involving wirexpro[.]com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f684e10ff1ffcdd32c62e73a11382896 2023-04-03 2023-04-03
HASH 9f85a07d4b4abff82ca18d990f062a84 2023-04-03 2023-04-03
HASH ec3f99dd7d9dbce8d704d407b086e84f 2023-04-03 2023-04-03
HASH 933508a9832da1150fcfdbc1ca9bc84c 2023-04-03 2023-04-03
HASH 96d3bbf4d2cf6bc452b53c67b3f2516a 2023-04-03 2023-04-03
DOMAIN wirexpro.com 2022-12-01 2023-04-03
DOMAIN oilycargo.com 2022-12-01 2023-04-03

Related Reports

« Back