3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible

2023-04-20 Mandiant

https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise

Thumbnail for 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible

Mandiant found that the 3CX Desktop App supply-chain compromise began with an earlier compromised X_TRADER installer from Trading Technologies, making it a cascading software supply-chain attack. The X_TRADER package deployed VEILEDSIGNAL through DLL side-loading, SIGFLIP, and DAVESHELL, while the later 3CX compromise distributed SUDDENICON and ICONICSTEALER and involved Windows and macOS build environment access. Mandiant tracks the 3CX activity as UNC4736, a suspected North Korean nexus cluster, and assesses with moderate confidence that it relates to financially motivated North Korean AppleJeus activity. Supporting evidence includes overlap with prior Google TAG reporting on Trading Technologies compromise, POOLRAT infrastructure using journalide[.]org, older POOLRAT links to CISA-reported AppleJeus activity, and weaker DNS overlap with suspected APT43 clusters.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 24d5dd3006c63d0f46fb33cbc1f5763… 2023-04-20 2025-12-17
HASH 5e40d106977017b1ed235419b1e59ff… 2021-02-17 2025-09-01
HASH c6441c961dcad0fe127514a918eaabd4 2023-04-20 2023-04-20
HASH ef4ab22e565684424b4142b1294f1f4d 2023-04-20 2023-04-20

Related Actors

Related Reports

« Back