Threat Advisory: 3CX Softphone Telephony Campaign
2023-03-30 • Todyl •
https://www.todyl.com/blog/post/threat-advisory-3cx-softphone-telephony-campaign
Todyl tracks the 3CX softphone compromise as a supply-chain attack attributed in the excerpt to LABYRINTH CHOLLIMA, a DPRK-associated actor. The malicious MSI distributed by the vendor contained a vulnerable executable and a malicious ffmpeg.dll that loaded into 3CXDesktopApp.exe, performed reflective DLL injection, and used an embedded key to decrypt later-stage content. The campaign used a GitHub IconStorages repository with Base64 data appended to icon files to retrieve C2 and additional payload information, with later reporting identifying an information-stealing stage that collected browser and system data. Todyl blocked known hashes and network indicators, hunted customer telemetry, and reported no successful callbacks among MXDR customers, but warned that exposed organizations should assess stored browser credentials and possible extortion risk.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | fad482ded2e25ce9e1dd3d3ecc3227a… | 2023-03-29 | 2023-04-28 |
| HASH | aa124a4b4df12b34e74ee7f6c683b2e… | 2023-03-29 | 2023-04-28 |
| HASH | 72349cf4971607c1bc66314069f0c86… | 2023-03-30 | 2023-03-30 |
| HASH | 5d99efa36f34aa6b43cd81e77544961… | 2023-03-30 | 2023-03-30 |