X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe
2023-04-21 • Symantec •
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain
Symantec found that the North Korean-linked X_TRADER supply-chain attack affected organizations beyond 3CX, including two energy-sector critical infrastructure victims in the United States and Europe and two financial-trading organizations. The campaign began with a trojanized X_TRADER installer that dropped side-loaded DLLs under C:\Programdata\TPM and installed VEILEDSIGNAL, a modular backdoor with process-injection and command-and-control components. Symantec noted that the activity appeared financially motivated because X_TRADER served futures trading users, but the compromise of strategic energy organizations raised concern that North Korean operators could later exploit access for espionage or further operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6e989462acf2321ff671eaf91b4e393… | 2023-04-21 | 2023-04-21 |
| HASH | aa318070ad1bf90ed459ac34dc5254a… | 2023-04-21 | 2023-04-21 |
| HASH | f8c370c67ffb3a88107c9022b17382b… | 2023-04-21 | 2023-04-21 |
| HASH | 277119738f4bdafa1cde9790ec82ce1… | 2023-04-21 | 2023-04-21 |
| HASH | 19442d9e476e3ef990ce57b68319030… | 2023-04-21 | 2023-04-21 |
| HASH | cb374af8990c5f47b627596c74e2308… | 2023-04-21 | 2023-04-21 |
| HASH | 47a8e3b20405a23f7634fa296f148ca… | 2023-04-21 | 2023-04-21 |
| HASH | e185c99b3d1085aed9fda65a9774abd… | 2023-04-21 | 2023-04-21 |
| HASH | d937e19ccb3fd1dddeea3eaaf72645e… | 2023-04-21 | 2023-04-21 |
| HASH | 900b63ff9b06e0890bf642bdfcbfcc6… | 2023-04-21 | 2023-04-21 |
| HASH | cc4eedb7b1f77f02b962f4b05278fa7… | 2023-04-21 | 2023-04-21 |
| URL | https://www.tradingtechnologies… | 2023-04-21 | 2023-04-21 |
| HASH | 6e11c02485ddd5a3798bf0f77206f2b… | 2023-04-20 | 2023-04-21 |