"Double Supply Chain Attack Behind 3CX Hack"

1 min read
Source: BleepingComputer
"Double Supply Chain Attack Behind 3CX Hack"
Photo: BleepingComputer
TL;DR

The recent supply chain attack on 3CX was caused by a previous supply chain compromise at Trading Technologies, where North Korean hackers breached the site to push trojanized software builds. The attackers used harvested credentials to move laterally through 3CX's network, eventually breaching both the Windows and macOS build environments. The malware achieved persistence through DLL side-loading via legitimate Microsoft Windows binaries, which made it harder to detect. The threat group (UNC4736) is related to the financially motivated North Korean Lazarus Group behind Operation AppleJeus.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer