logo

36gate: supply chain attack

ID: 32b3a6f1-6245-5f38-80a5-79d043ac466d

STIX ID: report--32b3a6f1-6245-5f38-80a5-79d043ac466d

Feed Name: Group-IB Blog

Threat Score
90/100

Date Published: 2023-03-31

Date Updated: 2026-04-27

...
...

Group-IB documents a March 2023 supply-chain compromise of the 3CX Desktop App in which attackers trojanized signed Windows and macOS installers (malicious ffmpeg.dll / libffmpeg components) that deploy encrypted shellcode and a downloader contacting numerous cloud-like C2 domains; the report includes technical analysis, extensive IoCs (hashes, domains, filesystem artifacts), mitigation guidance (uninstall/update, hunt with YARA/Sigma/EDR), and notes tentative links to a DPRK-nexus APT though attribution remains unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.