#Gopuram

Malware/Tool

2023-04-03 • Not just an infostealer: Gopuram backdoor deployed through 3CX supply chain attack

Gopuram is a backdoor delivered through the compromised 3CXDesktopApp supply chain. Trojanized Windows MSI installers contained an infected DLL that decrypted and executed shellcode stored in the overlay of d3dcompiler_47.dll. A macOS installer was also trojanized as part of the wider operation. After execution, the decrypted Gopuram payload recovered command-and-control server URLs from icons hosted in a GitHub repository and connected to one of the decoded destinations, providing the attackers with backdoor access beyond the operation's information-stealing component.

Tagged Reports

« Back