logo

Technical Analysis of Files Used in 3CX Desktop App Malware Campaign

ID: 348c5f9c-885c-5182-a307-48913a3925c2

STIX ID: report--348c5f9c-885c-5182-a307-48913a3925c2

Feed Name: CloudSEK Blog

Threat Score
85/100

Date Published: 2023-04-04

Date Updated: 2026-04-27

...
...

Trojanized, signed versions of the 3CX Desktop App delivered a multi-stage infection (ffmpeg.dll -> d3dcompiler_47.dll -> downloaded .ico files -> final payload) that decrypts C2 URLs and installs a previously unseen info stealer named ICONIC on Windows and macOS; the stealer exfiltrates browser history and potential sensitive URL data. The report provides detailed technical analysis, IoCs (hashes and URLs), and detection artifacts (YARA) and notes observations from CrowdStrike and Volexity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.