#ICONIC

Malware/Tool

2023-03-30 • 3CX Supply Chain Compromise Leads to ICONIC Incident

ICONIC is a Windows downloader used in the compromised 3CX Desktop application supply chain. A signed malicious update contained a modified ffmpeg.dll that the legitimate application loaded; the DLL decoded and injected ICONIC into memory. ICONIC then downloaded additional code disguised as icon files from a GitHub repository, leading to information-stealing activity on affected endpoints. The campaign was attributed in the source to a suspected North Korean actor and abused 3CX’s normal automatic-update process for broad delivery.

Tagged Reports

« Back