Technical Analysis of Files Used in 3CX Desktop App Malware Campaign
ID: 348c5f9c-885c-5182-a307-48913a3925c2
STIX ID: report--348c5f9c-885c-5182-a307-48913a3925c2
Feed Name: CloudSEK Blog
Trojanized, signed versions of the 3CX Desktop App delivered a multi-stage infection (ffmpeg.dll -> d3dcompiler_47.dll -> downloaded .ico files -> final payload) that decrypts C2 URLs and installs a previously unseen info stealer named ICONIC on Windows and macOS; the stealer exfiltrates browser history and potential sensitive URL data. The report provides detailed technical analysis, IoCs (hashes and URLs), and detection artifacts (YARA) and notes observations from CrowdStrike and Volexity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
