Security Update Mandiant Initial Results

2023-04-11 3CX

https://www.3cx.com/blog/news/mandiant-initial-results/

Thumbnail for Security Update Mandiant Initial Results

Windows-based Malware Mandiant determined that the attacker infected targeted 3CX systems with TAXHAUL (AKA “TxRLoader”) malware. The malware uses the Windows CryptUnprotectData API to decrypt the shellcode with a cryptographic key that is unique to each compromised host, which means the data can only be decrypted on the infected system. Mandiant identified that malware within the 3CX environment made use of the following command and control infrastructure: - azureonlinecloud[.]com - akamaicontainer[.]com Mandiant also identified a MacOS backdoor, currently named SIMPLESEA, located at /Library/Graphics/Quartz (MD5: d9d19abffc2c7dac11a16745f4aea44f).

Indicators of Compromise

Type Value First Seen Last Seen
HASH d9d19abffc2c7dac11a16745f4aea44f 2023-04-11 2023-10-05
DOMAIN journalide.org 2023-03-29 2023-05-09
DOMAIN akamaicontainer.com 2023-03-29 2023-04-28
DOMAIN azureonlinecloud.com 2023-03-29 2023-04-28
YARA TAXHAUL 2023-04-11 2023-04-11
DOMAIN msboxonline.com 2023-04-11 2023-04-11

Related Actors

Related Reports

2023-04-20 • 73% Match
#YARA #SupplyChain #3CXDesktopApp #SmoothOperator #UNC4736 #X_Trader #UNC4469 #UNC3782 #T1082 #T1140 #T1070.004 #T1071.001 #T1195.002 #T1112 #T1083 #T1497 #T1036 #T1027 #T1071 #T1195 #T1497.001 #T1105 #T1055 #T1620 #T1574.002 #T1622 #T1190 #T1588 #T1574 #T1573.002 #T1614 #T1573 #T1608 #T1070 #T1614.001 #T1071.004 #T1012 #T1588.004 #T1565.001 #T1036.001 #T1070.001 #T1608.003 #T1565
Shares tags: YARA, SupplyChain, 3CXDesktopApp • Published within a month
« Back