lazarusholic

Everyday is lazarus.dayβ

3CX SmoothOperator ffmpeg.dll with Binary Ninja

2023-04-03, struppigel
https://www.youtube.com/watch?v=fTX-vgSEfjk
#SupplyChain #3CXDesktopApp #SmoothOperator #Youtube

Contents

We analyze the trojanized ffmpeg.dll that was used in the supply chain attack called SmoothOperator. Me mark up the decompiled code in Binary Ninja and decrypt the next stage.