#SUDDENICON
Malware/Tool
SUDDENICON is malware associated with the March 2023 supply-chain compromise of the 3CXDesktopApp update process, affecting potentially impacted Windows and macOS clients. The malicious 3CX installer reportedly waited seven days after installation before retrieving additional material from GitHub and contacting command-and-control domains. Its infrastructure list was obtained by downloading icon files from the now-removed IconStorages GitHub repository and base64-decoding data appended to their trailing bytes. After reaching an active C2 server, the malware sent a POST request containing a machine identifier, then downloaded and decrypted another executable. Elastic described the execution flow as still under active investigation and warned that shellcode and process-injection alerts involving 3CX should not be allowlisted.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days