
The adversaries behind the supply chain attack targeting 3CX have deployed a second stage implant that specifically singles out a handful of cryptocurrency companies.
Russian cybersecurity company Kaspersky gopuram Since 2020, it has observed an increase in the number of infections in March 2023, coinciding with the 3CX compromise.
Gopuram’s primary function is to connect to a command and control (C2) server and deliver further instructions that allow the attacker to interact with the victim’s file system, create processes, and launch up to eight in-memory modules. to wait.
A backdoor link to North Korea detailed an attack on an unnamed cryptocurrency company in Southeast Asia in 2020, stating that “AppleJeus, a backdoor attributed to Korean-speaking threat actor Lazarus, and victims It is derived from the fact that it coexisted with the machine.
Targeting cryptocurrency companies is another telltale sign that Lazarus Group is involved. Given that attackers have repeatedly focused on the financial sector to generate illicit profits in sanctioned countries.
Kaspersky further states that it has identified a C2 that overlaps with the server (“wirexpro[.]com”) was previously identified as being used in an AppleJeus campaign documented by Malwarebytes in December 2022.
“Less than 10 infected machines with the Gopuram backdoor deployed indicate that the attackers used Gopuram with surgical precision,” the company noted, with the highest numbers in Brazil, Germany, Italy and France. infection rate was detected.
While the attack chains discovered so far involve using a malicious installer to distribute an information-stealing tool (known as the ICONIC Stealer), the latest findings suggest that the ultimate goal of the campaign is , suggesting that it may have been to infect the target with a full-fledged modular backdoor.
However, it is not known how successful this campaign was, or whether it led to actual theft of sensitive data or cryptocurrency. may have identified a target for exploitation of
The development comes as BlackBerry reveals that “the first phase of this operation will take place sometime between late summer and early fall 2022.”
According to the Canadian firm, most of the attack attempts were registered in Australia, the US and the UK, with healthcare, pharmaceuticals, IT and finance emerging as the targeted sectors.
It is unknown at this time how the attackers gained initial access to the 3CX network and whether it involved exploiting known or unknown vulnerabilities. This compromise is tracked under the identifier CVE-2023-29059.
Become an Incident Response Pro!
Unlocking the Secrets of Bulletproof Incident Response – Master the 6-step process with Asaf Perlman, IR Lead at Cynet!
Don’t miss it – secure your seat!
Evidence gathered so far indicates that attackers poisoned 3CX’s development environment and distributed Trojanized versions of legitimate apps to the company’s downstream customers in supply chain attacks like SolarWinds or Kaseya. I’m here.
One of the malicious components responsible for getting the infostealer, a library named ‘d3dcompiler_47.dll’, was armed with a decade-old Windows flaw (CVE-2013-3900) to disable Microsoft. It has also been found to embed encrypted shellcode without having to – issued signature.
It’s worth noting here that the ZLoader malware campaign, discovered by Israeli cybersecurity firm Check Point Research in January 2022, employed the same technique.
Multiple versions of the desktop app are affected: 18.12.407 and 18.12.416 for Windows and 18.11.1213, 18.12.402, 18.12.407, 18.12.416 for macOS. 3CX has said it has since directed the attack to “experienced and knowledgeable hackers.”
CrowdStrike has linked the incident to a nation-state group affiliated with North Korea that it tracks under the name Labyrinth Chollima, a sub-cluster within the Lazarus Group.