A Comprehensive Analysis of the 3CX Attack
ID: 5bc6a24f-4a3f-58aa-a091-41e2a52c1656
STIX ID: report--5bc6a24f-4a3f-58aa-a091-41e2a52c1656
Feed Name: Cyble Blog
A widespread supply-chain compromise of the 3CX DesktopApp delivered a digitally signed Trojanized installer (Windows and macOS) that drops malicious DLLs (ffmpeg.dll and d3dcompiler_47.dll). The ffmpeg DLL decrypts embedded shellcode via RC4 which loads an embedded DLL that waits seven days, retrieves Base64 + AES-GCM encrypted C2 URLs from ICO files in a GitHub repo, and downloads a final stealer capable of harvesting system information and browser credentials; the campaign affected a large installed base (3CX claims ~600,000 companies / 12M daily users) and includes numerous IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
