Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack

2023-04-03 • Kaspersky •

https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/

Thumbnail for Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack

Kaspersky investigated whether the 3CX supply-chain compromise led only to an infostealer or also to follow-on implants, and found Gopuram backdoor deployments tied to infected 3CXDesktopApp processes. The report says Gopuram infections rose in March 2023 and were specifically observed against cryptocurrency companies, with persistence through malicious DLLs such as wlbsctrl.dll and encrypted shellcode stored under the Windows TxR path. Gopuram’s main module, guard64.dll, connects to C2 and supports file-system interaction, process creation, registry and service manipulation, timestomping, injection, driver-loading support, updates, and partial net-command functionality. Kaspersky attributes the 3CX campaign to Lazarus with medium to high confidence based on Gopuram’s prior coexistence with AppleJeus at a Southeast Asian cryptocurrency company, Lazarus-aligned targeting of cryptocurrency firms, and infrastructure overlap involving wirexpro[.]com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f684e10ff1ffcdd32c62e73a11382896 2023-04-03 2023-04-03
HASH 9f85a07d4b4abff82ca18d990f062a84 2023-04-03 2023-04-03
HASH 6ce5b6b4cdd6290d396465a1624d489… 2023-04-03 2023-04-03
HASH 96d3bbf4d2cf6bc452b53c67b3f2516a 2023-04-03 2023-04-03
HASH 295c20d0f0a03fd8230098fade0af91… 2022-12-01 2023-04-03
DOMAIN wirexpro.com 2022-12-01 2023-04-03
DOMAIN oilycargo.com 2022-12-01 2023-04-03

Related Reports

« Back