SmoothOperator Campaign Trojanizes 3CXDesktopApp
2023-04-03 • Hive Pro •
Attachments
HivePro’s advisory attributes the SmoothOperator 3CX supply-chain campaign to LABYRINTH CHOLLIMA, listing aliases including HIDDEN COBRA, ZINC, Nickel Academy, and Lazarus Group, and describes worldwide targeting across automotive, food and beverage, hospitality, MSP, and manufacturing sectors. The attack used rigged 3CXDesktopApp installers for affected versions 18.12.407 and 18.12.416, then loaded a sideloaded malicious DLL and encrypted payload embedded in another DLL. The chain retrieved ICO files from GitHub that contained download URIs and ultimately led to ICONIC Stealer/SUDDENICON, with behavior including beaconing, second-stage deployment, and limited hands-on-keyboard manipulation. The source is largely an actionable advisory, providing MITRE ATT&CK categories and representative IOCs such as akamaitechcloudservices[.]com/v2/storage, glcloudservice[.]com/v1/console, pbxsources[.]com/exchange, protonmail addresses, and multiple file hashes.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | visualstudiofactory.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | akamaitechcloudservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msedgepackageinfo.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageazure.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azureonlinestorage.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | zacharryblogs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officestoragebox.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxphonenetwork.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | sourceslabs.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officeaddons.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | glcloudservice.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxcloudeservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azuredeploystore.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxsources.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageboxes.com | 2023-03-29 | 2024-09-09 |
| HASH | 9e9a5f8d86356796162cee881c843cd… | 2023-04-01 | 2023-06-29 |
| HASH | 769383fc65d1386dd141c960c997011… | 2023-03-29 | 2023-06-29 |
| HASH | 3dc840d32ce86cebf657b17cef62814… | 2023-03-29 | 2023-06-29 |
| HASH | cad1120d91b812acafef7175f949dd1… | 2023-03-29 | 2023-05-02 |
| [email protected] | 2023-04-03 | 2023-04-03 | |
| [email protected] | 2023-04-03 | 2023-04-03 | |
| DOMAIN | msedgeupdate.net | 2023-03-30 | 2023-04-03 |
| HASH | bf939c9c261d27ee7bb92325cc58862… | 2023-03-29 | 2023-04-03 |
| HASH | 20d554a80d759c50d6537dd7097fed8… | 2023-03-29 | 2023-04-03 |