惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Vercel News
Vercel News
博客园_首页
Y
Y Combinator Blog
美团技术团队
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
aimingoo的专栏
aimingoo的专栏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
MyScale Blog
MyScale Blog
GbyAI
GbyAI
人人都是产品经理
人人都是产品经理
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
博客园 - Franky
Engineering at Meta
Engineering at Meta
量子位
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
N
Netflix TechBlog - Medium

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
3CX VoIP Desktop Application Supply Chain Attack
Intel 471 · 2023-04-01 · via Intel 471 Blog

Threat Summary

The 3CX DesktopApp is a voice and video conferencing software developed by 3CX - a widely used application, utilized by an estimated 600,000 companies. However, attackers potentially linked to North Korea have trojanized the app's installers for several recent versions, delivering additional information-stealing malware to the victim's computer - the afflicted Windows versions being 18.12.407 and 18.12.416, and the afflicted Mac versions being 8.11.1213 to the latest package available. The attackers compromised the installers, which contain clean versions of the app along with malicious DLLs that sideloaded the malware that led to compromise. The malware contained shellcode and a third DLL that extracts and transmits stolen information to the attackers. Due to the campaign and details of the attack being unfolded and further understood, this malware campaign should be ascertained and prepared for.

Threat Synopsis - 3CX VoIP Supply Chain Attack

The 3CX DesktopApp, a commonly used desktop client for voice and video calling, has been infiltrated with a Trojan by attackers suspected to have links to North Korea. The attackers have altered installers for recent Windows and Mac versions of the software and abused them to deliver malware that could steal information from the victim's computers. By gathering this data, the attackers could determine whether the victim was a potential candidate for further compromise. Researchers suggest that the method utilized in this attack is reminiscent of the notorious SolarWinds attack that affected thousands of organizations.

The attack has been observed to compromise the installer files for two Windows versions (18.12.407 and 18.12.416) and two Mac versions (8.11.1213 to the latest at publication) of the app - with the associated MSI installer downloading the malicious DLL files, which extract an encrypted payload and execute it. more specifically, when downloaded, the clean installers included were exploited to sideload a malicious DLL (named ffmpeg.dll) that installed information-stealing malware on the computer. The DLL contained code that enabled it to execute a payload from a second DLL (named d3dcompiler_47.dll). The decrypted blob contained shellcode and a third DLL (which was seen to sleep for a week before calling out to associated C2 servers), which attempted to download an ICO file (observed as hxxps://raw.githubusercontent[].com/IconStorages/images/main/icon%d.ico) - which contains Base64 encoded strings, that the first-stage malware uses to download a final payload to the compromised devices, a previously unknown information-stealing malware downloaded as a DLL. This new malware has the capability to compromise/steal data, system information and stored credentials from Chrome, Edge, Brave, and Firefox user profiles.

GET THE FREE HUNT PACKAGES!

CHECK OUT OTHER EMERGING THREATS >