36gate: supply chain attack
ID: 32b3a6f1-6245-5f38-80a5-79d043ac466d
STIX ID: report--32b3a6f1-6245-5f38-80a5-79d043ac466d
Feed Name: Group-IB Blog
Group-IB documents a March 2023 supply-chain compromise of the 3CX Desktop App in which attackers trojanized signed Windows and macOS installers (malicious ffmpeg.dll / libffmpeg components) that deploy encrypted shellcode and a downloader contacting numerous cloud-like C2 domains; the report includes technical analysis, extensive IoCs (hashes, domains, filesystem artifacts), mitigation guidance (uninstall/update, hunt with YARA/Sigma/EDR), and notes tentative links to a DPRK-nexus APT though attribution remains unconfirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
