惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
Recent Announcements
Recent Announcements
Vercel News
Vercel News
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
H
Help Net Security
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog
G
Google Developers Blog
罗磊的独立博客
爱范儿
爱范儿
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园_首页
S
SegmentFault 最新的问题
WordPress大学
WordPress大学
月光博客
月光博客
人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
3CX VoIP Desktop Application Supply Chain Attack
Intel 471 · 2023-04-01 · via Intel 471 Blog

Threat Summary

The 3CX DesktopApp is a voice and video conferencing software developed by 3CX - a widely used application, utilized by an estimated 600,000 companies. However, attackers potentially linked to North Korea have trojanized the app's installers for several recent versions, delivering additional information-stealing malware to the victim's computer - the afflicted Windows versions being 18.12.407 and 18.12.416, and the afflicted Mac versions being 8.11.1213 to the latest package available. The attackers compromised the installers, which contain clean versions of the app along with malicious DLLs that sideloaded the malware that led to compromise. The malware contained shellcode and a third DLL that extracts and transmits stolen information to the attackers. Due to the campaign and details of the attack being unfolded and further understood, this malware campaign should be ascertained and prepared for.

Threat Synopsis - 3CX VoIP Supply Chain Attack

The 3CX DesktopApp, a commonly used desktop client for voice and video calling, has been infiltrated with a Trojan by attackers suspected to have links to North Korea. The attackers have altered installers for recent Windows and Mac versions of the software and abused them to deliver malware that could steal information from the victim's computers. By gathering this data, the attackers could determine whether the victim was a potential candidate for further compromise. Researchers suggest that the method utilized in this attack is reminiscent of the notorious SolarWinds attack that affected thousands of organizations.

The attack has been observed to compromise the installer files for two Windows versions (18.12.407 and 18.12.416) and two Mac versions (8.11.1213 to the latest at publication) of the app - with the associated MSI installer downloading the malicious DLL files, which extract an encrypted payload and execute it. more specifically, when downloaded, the clean installers included were exploited to sideload a malicious DLL (named ffmpeg.dll) that installed information-stealing malware on the computer. The DLL contained code that enabled it to execute a payload from a second DLL (named d3dcompiler_47.dll). The decrypted blob contained shellcode and a third DLL (which was seen to sleep for a week before calling out to associated C2 servers), which attempted to download an ICO file (observed as hxxps://raw.githubusercontent[].com/IconStorages/images/main/icon%d.ico) - which contains Base64 encoded strings, that the first-stage malware uses to download a final payload to the compromised devices, a previously unknown information-stealing malware downloaded as a DLL. This new malware has the capability to compromise/steal data, system information and stored credentials from Chrome, Edge, Brave, and Firefox user profiles.

GET THE FREE HUNT PACKAGES!

CHECK OUT OTHER EMERGING THREATS >