Massive supply chain attack targeting small number of crypto companies: Kaspersky

Share This Post

Crowdstrike and Kaspersky found an infection in a communications app that delivered a backdoor, but deployed it only a few times.

A supply chain attack installed a backdoor in computers around the world but has only been deployed in fewer than ten computers, cybersecurity company Kaspersky has reported. The deployments showed a particular interest in cyptocurrency companies, it added. 

Cybersecurity company Crowdstrike reported on March 29 that it has identified malicious activity on the 3CX softphone app 3CXDesktopApp. The app is marketed to corporate clients. The malicious activity detected included “beaconing to actor-controlled infrastructure, deployment of second-stage payloads, and, in a small number of cases, hands-on-keyboard activity.”

Kaspersky said it suspected the involvement of the North Korea-linked threat actor Labyrinth Chollima. 3CX said of the infection:

“This appears to have been a targeted attack from an Advanced Persistent Threat, perhaps even state sponsored, that ran a complex supply chain attack and picked who would be downloading the next stages of their malware.”

Kaspersky was already investigating a dynamic link library (DLL) found in one of the infected 3CXDesktopApp .exe file, it said. The DLL in question had been used to deliver the Gopuram backdoor, although it was not the only malicious payload deployed in the attack. Gopuram has been found to coexist with the AppleJeus backdoor attributed to the North Korean Lazarus group, Kaspersky added.

Related: North Korean hackers are pretending to be crypto VCs in new phishing scheme — Kaspersky

Infected 3CX software has been detected around the world, with highest infection figures in Brazil, Germany, Italy and France. Gopuram has been deployed in fewer than ten computers, however, in a display of “surgical precision,” Kaspersky said. It had found a Gopuram infection in a Southeast Asian cryptocurrency company in the past.

The 3CX app is used by over 600,000 companies, including several major brands, Kapersky said, citing the maker. The infected app had DigiCert certification.

Magazine: 4 out of 10 NFT sales are fake: Learn to spot the signs of wash trading

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Bitwise expects options trading for its Bitcoin ETF to start tomorrow

Bitwise CEO Hunter Horsley announced that options trading on the firm’s Bitcoin ETF product BITB will commence on Nov 20 In a Nov 19 post on X, Horsley stated: “We expect options on the

Toncoin Price Analysis: TON Price Eyes To Hit $8 Next?

The post Toncoin Price Analysis: TON Price Eyes To Hit $8 Next appeared first on Coinpedia Fintech News Story Highlights Toncoin price soared 996% in the last seven days The TON price surpassed

Solana (SOL) Outpaces BTC as Solana DEX Records $41B Weekly Volume!

The post Solana (SOL) Outpaces BTC as Solana DEX Records $41B Weekly Volume! appeared first on Coinpedia Fintech News Solana (SOL) has caught the attention of the crypto market, rising 247% to reach

XRP On Fire: Over 90% Weekly Growth Catapults Altcoin To Fresh 2-Year High

XRP peaked to $126, marking a new two-year-high for the coin The uplift in the value of XRP has happened at a time when the rest of the cryptocurrency market anticipates some regulatory overhauls in

Is Solana Going To Dethrone Ethereum?

The post Is Solana Going To Dethrone Ethereum appeared first on Coinpedia Fintech News Solana is turning heads in the crypto world, especially after its strong performance against Bitcoin The SOL/BTC

Softwar author Jason Lowery looks to White House role advising on Bitcoin national security

Jason Lowery, a major in the US Space Force, has submitted an application to serve as a military advisor on the National Security Council (NSC) and the White House Office of Science & Technology