Red flags flew over software supply chain-compromised 3CX update

2023-03-30 Reversing Labs

https://www.reversinglabs.com/blog/red-flags-fly-over-supply-chain-compromised-3cx-update

Thumbnail for Red flags flew over software supply chain-compromised 3CX update

ReversingLabs found that compromised 3CXDesktopApp updates likely resulted from tampering in the 3CX software build pipeline or a malicious dependency, placing malicious code inside signed VoIP client packages downloaded by customers. The attack modified Electron components: ffmpeg was changed to extract and run RC4-encrypted shellcode appended to the signed d3dcompiler_47.dll file, with tooling signatures linked to SigFlip and SigLoader. CrowdStrike attributed the wider intrusion activity to LABYRINTH CHOLLIMA, a North Korea-associated actor, and reported hands-on-keyboard activity in some affected customer environments. The incident mattered because 3CX software was used by hundreds of thousands of organizations, and the visible binary differences showed how differential analysis could have surfaced suspicious post-signing modification before customer systems were exposed.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 769383fc65d1386dd141c960c997011… 2023-03-29 2023-06-29
HASH 3dc840d32ce86cebf657b17cef62814… 2023-03-29 2023-06-29
HASH 3b88cda62cdd918b62ef5aa8c5a73a4… 2023-03-30 2023-05-02
HASH bf939c9c261d27ee7bb92325cc58862… 2023-03-29 2023-04-03
HASH 20d554a80d759c50d6537dd7097fed8… 2023-03-29 2023-04-03
HASH bea77d1e59cf18dce22ad9a2fad5294… 2023-03-30 2023-03-31
HASH f7f1b34c2770d83e2250e19c8425a4b… 2023-03-30 2023-03-31
HASH 8433a94aedb6380ac8d4610af643fb0… 2023-03-30 2023-03-31
HASH 188754814b37927badc988b45b7c7f7… 2023-03-30 2023-03-31
HASH ff3dd457c0d00d00d396fdf6ebe7c25… 2023-03-30 2023-03-31
HASH bfecb8ce89a312d2ef4afc64a63847a… 2023-03-30 2023-03-31
HASH 19f4036f5cd91c5fc411afc4359e32f… 2023-03-30 2023-03-31
HASH 6285ffb5f98d35cd98e78d48b63a05a… 2023-03-30 2023-03-31
HASH b2a89eebb5be61939f5458a024c929b… 2023-03-30 2023-03-31
HASH 354251ca9476549c391fbd5b87e81a2… 2023-03-30 2023-03-30
HASH 8b81f6012fd748f0fed53eeef721644… 2023-03-30 2023-03-30
HASH 5b0582632975d230c8f73c768b9ef39… 2023-03-30 2023-03-30

Related Reports

« Back