Threat Advisory: 3CX Softphone Telephony Campaign

2023-03-30 Todyl

https://www.todyl.com/blog/post/threat-advisory-3cx-softphone-telephony-campaign

Thumbnail for Threat Advisory: 3CX Softphone Telephony Campaign

Todyl tracks the 3CX softphone compromise as a supply-chain attack attributed in the excerpt to LABYRINTH CHOLLIMA, a DPRK-associated actor. The malicious MSI distributed by the vendor contained a vulnerable executable and a malicious ffmpeg.dll that loaded into 3CXDesktopApp.exe, performed reflective DLL injection, and used an embedded key to decrypt later-stage content. The campaign used a GitHub IconStorages repository with Base64 data appended to icon files to retrieve C2 and additional payload information, with later reporting identifying an information-stealing stage that collected browser and system data. Todyl blocked known hashes and network indicators, hunted customer telemetry, and reported no successful callbacks among MXDR customers, but warned that exposed organizations should assess stored browser credentials and possible extortion risk.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fad482ded2e25ce9e1dd3d3ecc3227a… 2023-03-29 2023-04-28
HASH aa124a4b4df12b34e74ee7f6c683b2e… 2023-03-29 2023-04-28
HASH 72349cf4971607c1bc66314069f0c86… 2023-03-30 2023-03-30
HASH 5d99efa36f34aa6b43cd81e77544961… 2023-03-30 2023-03-30

Related Reports

« Back