Elastic users protected from SUDDENICON’s supply chain attack
ID: 1026dd3b-b77a-5f82-afa6-0ac3ab002174
STIX ID: report--1026dd3b-b77a-5f82-afa6-0ac3ab002174
Feed Name: Elastic Security Labs
Elastic Security Labs reports a supply-chain compromise of the 3CXDesktopApp in which installers dropped backdoored libraries (ffmpeg.dll and d3dcompiler_47.dll) that extract and inject a delayed shellcode loader called SUDDENICON; the loader waits ~7 days, retrieves C2 domains embedded in GitHub-staged icon files, and downloads a second-stage information-stealer. The analysis includes affected file hashes and installer filenames, potentially malicious domains, KQL/EQL hunting queries, YARA rules, and mitigation guidance urging prevention-mode shellcode protections and removal of compromised clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
