#WeeklyCTI

Опубликовано: 11 Июнь 2026
на канале: Daniel Lowrie
771
52

I can't imagine what other topic could be covered this week except for the 3CX supply-chain attack, so I turned on the camera in the middle of the night to record my thoughts (which are mostly just sleep-deprived ramblings 🤪).

But instead of focusing so much on "WHAT HAPPENED", I want to shift our focus to more of "WHAT WE CAN LEARN". What can we learn from the tactics, tools, and techniques behind the attack? How can we utilize that knowledge to increase our security?

Buy Me A Coffee:
https://www.buymeacoffee/danielowrie

==============
Links
==============
https://www.darkreading.com/endpoint/...
https://www.crowdstrike.com/blog/crow...
https://blog.checkpoint.com/2023/03/2...
https://www.huntress.com/blog/3cx-voi...
https://www.cyberreason.com/blog/thre...
https://crypt0ace.github.io/posts/DLL...

==============
Show Notes
==============
What happened?
https://www.darkreading.com/endpoint/...
https://www.crowdstrike.com/blog/crow...
By means unconfirmed
3CX issued malicious update
Signed code, from 3CX
DesktopApp update
Malicious Activity
Beaconing to C2
2nd-Stage Payload
A SMALL BIT of Hands-on-keyboard activity
Attribution
https://www.huntress.com/blog/3cx-voi...
DPRK (Democratic People's Republic of Korea)
Labyrinth Chollima

BUT WHAT CAN WE LEARN???
*Supply chain attack* = scariest environment imaginable
It's not just a breach that affects 1 org
It potentially affects the org's customer base
Makes the attack exponentially worse

*DLL Side-Loading*
What is DLL Side-Loading?
https://www.cyberreason.com/blog/thre...
https://crypt0ace.github.io/posts/DLL...
Has example
ffmpeg.dll (malicious, not the real one)
Reads encrypted data from another malicious DLL
RC4 Decrypt Key (Huntress)
The DPRK "fingerprint"
d3dcompiler_47.dll
Downloads URL list
Github repo of icon files
b64 encoded info appended to icon files
Payload is downloaded from one of these URLs
Last payload executed

*Dylib Side-Loading*
Mac version of DLL Side-Loading
2 versions of the DesktopApp for Mac OS were compromised
libffmpeg.dylib
Ultimately makes a URL request

Mitigation
Uninstall DesktopApp
Use the Progressive Web App(PWA) instead
Clean update to DesktopApp is in the works
Yara rule
https://symantec-enterprise-blogs.sec...
Update AV/EDR Solutions
Malicious files and domains should be signatured by now

IoCs
FIle hashes
Malicious domains
Github repo (taken down)

==============
Chapters
==============
00:00 Intro
03:45 Overview of What Happened
08:05 Attribution
09:22 Main Topics
11:23 Supply-Chain Attacks
15:18 Crowdstrike's Article
17:40 DLL Side-Loading
29:50 Dylib Side-Loading
31:55 Mitigations
32:45 IoCs
34:22 Final Thoughts
===================

#cybersecurity #cti #supplychain #databreach #cicd #cyberthreats #cyberthreatintelligence #threatintelligence #malware #hacker #hacking #ethicalhacking #informationsecurity #infosec #3cx #cybersecurityawareness