SmoothOperator | Ongoing Campaign Trojanizes 3CXDesktopApp in Supply Chain Attack

2023-03-29 Sentinel One

https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/

Thumbnail for SmoothOperator | Ongoing Campaign Trojanizes 3CXDesktopApp in Supply Chain Attack

SentinelOne documented SmoothOperator as an active 3CXDesktopApp supply-chain campaign in which trojanized installers acted as the first stage of a multi-stage attack chain. The malicious application reflectively loaded a DLL, pulled ICO files with appended Base64 data from the GitHub repository github.com/IconStorages/images, and used that data to retrieve a further stage. SentinelOne reported that the final stage hash cad1120d91b812acafef7175f949dd1b09c6c21a implemented infostealer functionality against system data and Chrome, Edge, Brave, and Firefox browser artifacts. The source explicitly said the actor’s infrastructure had been registered as early as February 2022 but that SentinelOne did not yet see obvious connections to existing threat clusters, so the summary should not overstate attribution.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN akamaitechcloudservices.com 2023-03-29 2024-09-09
DOMAIN msedgepackageinfo.com 2023-03-29 2024-09-09
DOMAIN msstorageazure.com 2023-03-29 2024-09-09
DOMAIN azureonlinestorage.com 2023-03-29 2024-09-09
DOMAIN officestoragebox.com 2023-03-29 2024-09-09
DOMAIN pbxphonenetwork.com 2023-03-29 2024-09-09
DOMAIN officeaddons.com 2023-03-29 2024-09-09
DOMAIN glcloudservice.com 2023-03-29 2024-09-09
DOMAIN pbxcloudeservices.com 2023-03-29 2024-09-09
DOMAIN azuredeploystore.com 2023-03-29 2024-09-09
DOMAIN pbxsources.com 2023-03-29 2024-09-09
DOMAIN msstorageboxes.com 2023-03-29 2024-09-09
DOMAIN journalide.org 2023-03-29 2023-05-09
HASH cad1120d91b812acafef7175f949dd1… 2023-03-29 2023-05-02
DOMAIN qwepoi123098.com 2023-03-29 2023-04-28
DOMAIN akamaicontainer.com 2023-03-29 2023-04-28
DOMAIN dunamistrd.com 2023-03-29 2023-04-28
DOMAIN azureonlinecloud.com 2023-03-29 2023-04-28
HASH bf939c9c261d27ee7bb92325cc58862… 2023-03-29 2023-04-03
HASH 20d554a80d759c50d6537dd7097fed8… 2023-03-29 2023-04-03
DOMAIN convieneonline.com 2023-03-29 2023-03-30
DOMAIN soyoungjun.com 2023-03-29 2023-03-30

Related Reports

« Back