iTnews Asia
  • Home
  • News
  • Security

Mandiant says 3CX attack probably came from North Korea

Mandiant says 3CX attack probably came from North Korea

Security update on the way.

By Richard Chirgwin on Apr 12, 2023 11:43AM

A report prepared by Google’s Mandiant security business identifies a North Korean hacking team as the most likely source of a supply chain attack against a softphone made by 3CX.

The attack emerged in late March when security scans by SentinelOne and CrowdStrike barred the software.

At the time, SentinelOne said that "the trojanised 3CXDesktopApp is the first stage in a multi-stage attack chain that pulls ICO files appended with base64 data from GitHub and ultimately leads to a third stage infostealer DLL still being analysed as of the time of writing”.

3CX warned users to uninstall the desktop version and switch to a Web version, and engaged Mandiant to find out what had happened.

CEO Nick Galea has now detailed the initial results of Mandiant’s work.

According to Galea, Mandiant attributed the attack to “a cluster named UNC4736."

"Mandiant assesses with high confidence that UNC4736 has a North Korean nexus.”

Windows systems, Galea said, were attacked with a loader called TAXHAUL, while MacOS attacks used a backdoor called SIMPLESEA, which Mandiant is still analysing.

The Windows attacks achieved persistence via DLL side-loading, and command and control domains the malware used included azureonlinecloud[.]com, akamaicontainer[.]com, journalide[.]org and msboxonline[.]com.

In a separate post, Galea also promised a security-only update of the 3CX software.

A QA release of the update is expected this week, he said, with alpha and beta releases next week ahead of general availability.

Security features of the update will include hashing of all web login passwords to remove admin access to them; removal of security information including passwords from the welcome email; and web admin access will be restricted by IP address.

While there will be an update to the desktop client, 3CX still recommends users favour the web application.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
3cx north korea security simplesea taxhaul

Related Articles

  • Your organisation’s physical security can be a gateway for cybercriminals
  • The best way to outsmart your threat actors is to think like one
  • How cybercriminals are exploiting LLMs to harm your business
  • Is identity now the next parameter of cybersecurity breaches?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The best way to outsmart your threat actors is to think like one

The best way to outsmart your threat actors is to think like one

Your organisation’s physical security can be a gateway for cybercriminals

Your organisation’s physical security can be a gateway for cybercriminals

What are the most pressing cyber security concerns going into 2025?

What are the most pressing cyber security concerns going into 2025?

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

Malaysia ramps up cyber security defense to stem rising fraud and ransomware attacks

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.