3CX Desktop Client Trojanized for Supply-Chain Attacks
ID: aa056bd9-b91f-5e73-b1bb-051ee4e3b9cf
STIX ID: report--aa056bd9-b91f-5e73-b1bb-051ee4e3b9cf
Feed Name: ReliaQuest Blog
Threat Score
ReliaQuest reports that a legitimately signed 3CX Desktop Client was trojanized in a supply-chain campaign (SmoothOperator) attributed to the Lazarus Group; the compromise uses a first-stage loader that fetches a second-stage infostealer via Base64-encoded icon files on GitHub, with observed C2 domains and IOCs, and customers are advised to uninstall the desktop client, disable automatic updates, and use the PWA client until remediation is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
