3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible

2023-04-20 • Mandiant •

https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise

Thumbnail for 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible

Mandiant found that the 3CX Desktop App supply-chain compromise began with an earlier compromised X_TRADER installer from Trading Technologies, making it a cascading software supply-chain attack. The X_TRADER package deployed VEILEDSIGNAL through DLL side-loading, SIGFLIP, and DAVESHELL, while the later 3CX compromise distributed SUDDENICON and ICONICSTEALER and involved Windows and macOS build environment access. Mandiant tracks the 3CX activity as UNC4736, a suspected North Korean nexus cluster, and assesses with moderate confidence that it relates to financially motivated North Korean AppleJeus activity. Supporting evidence includes overlap with prior Google TAG reporting on Trading Technologies compromise, POOLRAT infrastructure using journalide[.]org, older POOLRAT links to CISA-reported AppleJeus activity, and weaker DNS overlap with suspected APT43 clusters.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 24d5dd3006c63d0f46fb33cbc1f5763… 2023-04-20 2025-12-17
HASH 5e40d106977017b1ed235419b1e59ff… 2021-02-17 2025-09-01
HASH f8c370c67ffb3a88107c9022b17382b… 2023-04-20 2023-04-21
HASH fbc50755913de619fb830fb95882e97… 2023-04-20 2023-04-20

Related Actors

Related Reports

« Back