Lazarus and the 3CX Double Software Supply Chain Attack
2023-05-02 • Avertium •
https://explore.avertium.com/resource/lazarus-and-the-3cx-double-supply-chain-attack
The 3CX compromise is presented as a Lazarus-linked double software supply-chain incident: a trojanized X_TRADER application gave UNC4736 access to a 3CX employee system, enabling lateral movement into 3CX Windows and macOS build environments and malicious code injection into the desktop app. The source ties the intrusion to North Korean activity through Mandiant, ESET, and Kaspersky reporting, including VEILEDSIGNAL, POOLRAT/SIMPLESEA discussion, Gopuram deployment to some customers, and C2 overlap with SimplexTea. It also links the 3CX operation to Lazarus Operation DreamJob tradecraft, where a fake HSBC job-offer lure for Linux users delivered the SimplexTea backdoor via cloud storage.