Massive supply chain attack targeting small number of crypto companies: Kaspersky

Share This Post

Crowdstrike and Kaspersky found an infection in a communications app that delivered a backdoor, but deployed it only a few times.

A supply chain attack installed a backdoor in computers around the world but has only been deployed in fewer than ten computers, cybersecurity company Kaspersky has reported. The deployments showed a particular interest in cyptocurrency companies, it added. 

Cybersecurity company Crowdstrike reported on March 29 that it has identified malicious activity on the 3CX softphone app 3CXDesktopApp. The app is marketed to corporate clients. The malicious activity detected included “beaconing to actor-controlled infrastructure, deployment of second-stage payloads, and, in a small number of cases, hands-on-keyboard activity.”

Kaspersky said it suspected the involvement of the North Korea-linked threat actor Labyrinth Chollima. 3CX said of the infection:

“This appears to have been a targeted attack from an Advanced Persistent Threat, perhaps even state sponsored, that ran a complex supply chain attack and picked who would be downloading the next stages of their malware.”

Kaspersky was already investigating a dynamic link library (DLL) found in one of the infected 3CXDesktopApp .exe file, it said. The DLL in question had been used to deliver the Gopuram backdoor, although it was not the only malicious payload deployed in the attack. Gopuram has been found to coexist with the AppleJeus backdoor attributed to the North Korean Lazarus group, Kaspersky added.

Related: North Korean hackers are pretending to be crypto VCs in new phishing scheme — Kaspersky

Infected 3CX software has been detected around the world, with highest infection figures in Brazil, Germany, Italy and France. Gopuram has been deployed in fewer than ten computers, however, in a display of “surgical precision,” Kaspersky said. It had found a Gopuram infection in a Southeast Asian cryptocurrency company in the past.

The 3CX app is used by over 600,000 companies, including several major brands, Kapersky said, citing the maker. The infected app had DigiCert certification.

Magazine: 4 out of 10 NFT sales are fake: Learn to spot the signs of wash trading

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Optimism, Aptos, And Taiko Face $169.66 Million In Token Unlocks, Should You Buy Or Sell?

The cryptocurrency market is gearing up for a major event as Optimism (OP), Aptos (APT), and Taiko (TAIKO) prepare for token unlocks collectively valued at $16966 million According to data from

Silver Miners Unlikely to Meet Demand Even if Prices Keep Increasing

The silver market is facing a multi-year deficit product of the extraction dynamics and the increase in the metal’s demand Even with today’s high prices, silver production is unlikely to

Court greenlights FTX’s $16.5 billion bankruptcy plan to repay defrauded customers

Defunct crypto exchange FTX received court approval for its bankruptcy plan and its estate is now clear to repay customers in cash, with interest, using up to $165 billion in recovered assets,

FTX Bankruptcy Plan Approved: $16 Billion In Assets To Be Repaid, FTT Price Soars 20%

A US bankruptcy court has officially approved crypto exchange FTX liquidation plan, paving the way for it to repay customers using $16 billion in recovered assets, according to Reuters, which reports

Bitcoin News: Fewer And Fewer People Willing To Sell BTC

Bitcoin is a deflationary asset with a fixed supply, unlike Ethereum, whose supply increases or decreases yearly depending on network use There will be only 21 million BTC in circulation, and a

AI Cryptos Spike as Broader Market Stays Flat, Sector Nears $30B Milestone

While the crypto market’s overall capitalization has only ticked up by 028% over the past day, reaching $219 trillion, the artificial intelligence (AI) crypto economy has made more noticeable