SmoothOperator | Ongoing Campaign Trojanizes 3CXDesktopApp in Supply Chain Attack
2023-03-29 • Sentinel One •
SentinelOne documented SmoothOperator as an active 3CXDesktopApp supply-chain campaign in which trojanized installers acted as the first stage of a multi-stage attack chain. The malicious application reflectively loaded a DLL, pulled ICO files with appended Base64 data from the GitHub repository github.com/IconStorages/images, and used that data to retrieve a further stage. SentinelOne reported that the final stage hash cad1120d91b812acafef7175f949dd1b09c6c21a implemented infostealer functionality against system data and Chrome, Edge, Brave, and Firefox browser artifacts. The source explicitly said the actor’s infrastructure had been registered as early as February 2022 but that SentinelOne did not yet see obvious connections to existing threat clusters, so the summary should not overstate attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | akamaitechcloudservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msedgepackageinfo.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageazure.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azureonlinestorage.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officestoragebox.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxphonenetwork.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | officeaddons.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | glcloudservice.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxcloudeservices.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | azuredeploystore.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | pbxsources.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | msstorageboxes.com | 2023-03-29 | 2024-09-09 |
| DOMAIN | journalide.org | 2023-03-29 | 2023-05-09 |
| HASH | cad1120d91b812acafef7175f949dd1… | 2023-03-29 | 2023-05-02 |
| DOMAIN | qwepoi123098.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | akamaicontainer.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | dunamistrd.com | 2023-03-29 | 2023-04-28 |
| DOMAIN | azureonlinecloud.com | 2023-03-29 | 2023-04-28 |
| HASH | bf939c9c261d27ee7bb92325cc58862… | 2023-03-29 | 2023-04-03 |
| HASH | 20d554a80d759c50d6537dd7097fed8… | 2023-03-29 | 2023-04-03 |
| DOMAIN | convieneonline.com | 2023-03-29 | 2023-03-30 |
| DOMAIN | soyoungjun.com | 2023-03-29 | 2023-03-30 |