Understanding the magnitude of the 3CXDesktopApp phenomenon

2023-03-31 • Emanueledelucia •

https://www.emanueledelucia.net/understanding-the-magnitude-of-the-3cxdesktopapp-phenomenon/

Thumbnail for Understanding the magnitude of the 3CXDesktopApp phenomenon

The 3CXDesktopApp supply-chain compromise affected Windows and macOS builds of a widely used desktop communications application, with CrowdStrike identifying links between the activity and Lazarus Group. On Windows, the MSI installer executed 3CXDesktopApp.exe, which loaded a malicious ffmpeg.dll that searched for d3dcompiler_47.dll, decrypted an embedded payload using RC4, changed memory permissions, and staged a delayed loader. The loader was described as contacting a GitHub repository to retrieve .ICO files containing encrypted command-and-control strings, with a later payload assessed as a browser data stealer. Telemetry cited in the excerpt associated SmoothOperator infrastructure such as msstorageazure[.]com and akamaitechcloudservices[.]com with activity across multiple countries and sectors, including manufacturing, finance, hospitality, technology, industrial, and manufacturing environments.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN akamaitechcloudservices.com 2023-03-29 2024-09-09
DOMAIN msstorageazure.com 2023-03-29 2024-09-09
HASH c485674ee63ec8d4e8fde9800788175… 2023-03-30 2023-04-28
HASH 7986bbaee8940da11ce089383521ab4… 2023-03-29 2023-04-28

Related Reports

« Back