SmoothOperator Campaign Trojanizes 3CXDesktopApp

2023-04-03 Hive Pro

https://www.hivepro.com/wp-content/uploads/2023/04/SmoothOperator-Campaign-Trojanizes-3CXDesktopApp_TA2023167.pdf

Attachments

SmoothOperator-Campaign-Trojanizes-3CXDesktopApp_TA2023167.pdf (2 MB)

Thumbnail for SmoothOperator Campaign Trojanizes 3CXDesktopApp

HivePro’s advisory attributes the SmoothOperator 3CX supply-chain campaign to LABYRINTH CHOLLIMA, listing aliases including HIDDEN COBRA, ZINC, Nickel Academy, and Lazarus Group, and describes worldwide targeting across automotive, food and beverage, hospitality, MSP, and manufacturing sectors. The attack used rigged 3CXDesktopApp installers for affected versions 18.12.407 and 18.12.416, then loaded a sideloaded malicious DLL and encrypted payload embedded in another DLL. The chain retrieved ICO files from GitHub that contained download URIs and ultimately led to ICONIC Stealer/SUDDENICON, with behavior including beaconing, second-stage deployment, and limited hands-on-keyboard manipulation. The source is largely an actionable advisory, providing MITRE ATT&CK categories and representative IOCs such as akamaitechcloudservices[.]com/v2/storage, glcloudservice[.]com/v1/console, pbxsources[.]com/exchange, protonmail addresses, and multiple file hashes.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN visualstudiofactory.com 2023-03-29 2024-09-09
DOMAIN akamaitechcloudservices.com 2023-03-29 2024-09-09
DOMAIN msedgepackageinfo.com 2023-03-29 2024-09-09
DOMAIN msstorageazure.com 2023-03-29 2024-09-09
DOMAIN azureonlinestorage.com 2023-03-29 2024-09-09
DOMAIN zacharryblogs.com 2023-03-29 2024-09-09
DOMAIN officestoragebox.com 2023-03-29 2024-09-09
DOMAIN pbxphonenetwork.com 2023-03-29 2024-09-09
DOMAIN sourceslabs.com 2023-03-29 2024-09-09
DOMAIN officeaddons.com 2023-03-29 2024-09-09
DOMAIN glcloudservice.com 2023-03-29 2024-09-09
DOMAIN pbxcloudeservices.com 2023-03-29 2024-09-09
DOMAIN azuredeploystore.com 2023-03-29 2024-09-09
DOMAIN pbxsources.com 2023-03-29 2024-09-09
DOMAIN msstorageboxes.com 2023-03-29 2024-09-09
HASH 9e9a5f8d86356796162cee881c843cd… 2023-04-01 2023-06-29
HASH 769383fc65d1386dd141c960c997011… 2023-03-29 2023-06-29
HASH 3dc840d32ce86cebf657b17cef62814… 2023-03-29 2023-06-29
HASH cad1120d91b812acafef7175f949dd1… 2023-03-29 2023-05-02
EMAIL [email protected] 2023-04-03 2023-04-03
EMAIL [email protected] 2023-04-03 2023-04-03
DOMAIN msedgeupdate.net 2023-03-30 2023-04-03
HASH bf939c9c261d27ee7bb92325cc58862… 2023-03-29 2023-04-03
HASH 20d554a80d759c50d6537dd7097fed8… 2023-03-29 2023-04-03

Related Reports

« Back