UTA0040

2023-03-30 • Volexity3CX Supply Chain Compromise Leads to ICONIC Incid…

UTA0040 is Volexity's tracking name for a suspected North Korean threat actor associated with the 3CX software supply-chain compromise disclosed in March 2023. The operation delivered malicious, vendor-signed updates through 3CX's normal automatic update process to Windows and macOS endpoints. On Windows, a compromised media library decoded and injected an initial payload that retrieved encrypted command-and-control information from files hosted in a public code repository. A second-stage stealer collected system details and browser history and returned the data to attacker infrastructure, apparently enabling further payload delivery to selected hosts. The macOS installer contained an analogous malicious library and an encoded server list. Infrastructure and repository evidence indicated preparation from late 2022, while detection reports appeared in March 2023. The campaign demonstrated broad initial distribution, cross-platform development, staged reconnaissance, and selective follow-on access through a trusted software channel.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster