3CX supply chain attack analysis
ID: 27c8dc09-1ca2-5488-915b-1b77d9757bbe
STIX ID: report--27c8dc09-1ca2-5488-915b-1b77d9757bbe
Feed Name: Zscaler Security Research Blog
Executive summary: The report analyzes a supply-chain malware campaign that trojanized a signed 3CX Desktop App MSI (3CXDesktopApp-18.12.416.msi). The malicious ffmpeg.dll is side-loaded, locates an MS-signed d3dcompiler_47.dll containing RC4-encrypted shellcode (key: "3jB(2bsG#@c7"), decrypts and executes a second-stage DLL which downloads icon files from GitHub, extracts and decrypts a C2 URL (https://glcloudservice.com/v1/console), and eventually deploys an infostealer capable of harvesting saved browser credentials and system information.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
