North Korean hackers attack hundreds of thousands of companies globally

    WORLD  31 March 2023 - 19:24

    Researchers from several information security companies reported a large-scale hacking attack on users of 3CX Phone’s VoIP telephony applications.

    Attackers from the Labyrinth Chollima group, allegedly linked to the North Korean government, managed to integrate the trojan into 3CX applications for Windows and macOS, used by more than 600,000 companies worldwide, TechNewsSpace reports.

    According to available data, hackers managed to compromise 3CX’s software build system, which is used to create and distribute new versions of the company’s software products for Windows and macOS platforms. Control over this system gave attackers the ability to hide the trojan in legitimate VoIP telephony applications signed with a valid 3CX certificate. Because of this, millions of users could be at risk as 3CX applications are used by companies all over the world including American Express, Mercedes-Benz, Price Waterhouse Cooper and others.

    According to the source, versions of applications released in March this year could pose a threat. We are talking about versions 18.12.407 and 18.12.416 for Windows and 18.11.1213, 18.12.402, 18.12.407 and 18.12.416 for macOS. The attack mechanism is triggered when a user downloads an MSI installer from the 3CX website or downloads an update package. During the installation process, several malicious DLL files are extracted that are required for the next stage of the attack. Although the installer executable itself is not malicious, it uses the mentioned libraries to download, extract and execute the encrypted payload.

    After that, ICO files with additional lines of code are downloaded from GitHub repository, which are used to deliver the final payload to victims’ devices. The source notes that the first ICO files were added to GitHub in December last year. The malware itself is a previously unknown trojan horse designed to steal information, including logins and passwords stored in web browsers.

    3CX CEO Nick Galea wrote a message on the company’s forum, where he apologized for the incident. He also recommended that users remove versions of applications compromised by attackers and temporarily switch to using the web version of the softphone.

     

    Caliber.Az

    Subscribe to our Telegram channel


Read also

The Economist: What Asia’s economic revolution means for the world

23 September 2023 - 23:04

NASA's first asteroid sample on track for parachute landing in Utah

23 September 2023 - 22:00

Dubious Russian claims of ‘doubling’ arms production

24 September 2023 - 08:03

Prince Harry and Meghan join Kevin Costner for fundraiser

24 September 2023 - 07:04

Crimea rocked by explosions again after Black Sea Fleet HQ strike

24 September 2023 - 06:04

Ex-Wagner commander arrested in Norway for attempting return to Russia

23 September 2023 - 21:03
ADVERTS
Video
Latest news

    Dubious Russian claims of ‘doubling’ arms production

    24 September 2023 - 08:03

    Prince Harry and Meghan join Kevin Costner for fundraiser

    24 September 2023 - 07:04

    Crimea rocked by explosions again after Black Sea Fleet HQ strike

    24 September 2023 - 06:04

    Maryland, Virginia governors declare state of emergency as Tropical Storm Ophelia approaches

    24 September 2023 - 05:03

    Zelenskyy visit shows McCarthy walks ‘thin line’ on Ukraine aid

    24 September 2023 - 04:03

    Political class betrays Brexit by turning Britain into European country

    24 September 2023 - 03:05

    EU negotiator says trade relations with China ‘very imbalanced’

    24 September 2023 - 02:04

    Germany’s Baerbock joins chorus criticizing EU migration deal with Tunisia

    24 September 2023 - 01:03

    South Korea, US, Japan to take tough measures against Russia-North Korea arms deal

    24 September 2023 - 00:03

    The Economist: What Asia’s economic revolution means for the world

    23 September 2023 - 23:04

    NASA's first asteroid sample on track for parachute landing in Utah

    23 September 2023 - 22:00

    Ex-Wagner commander arrested in Norway for attempting return to Russia

    23 September 2023 - 21:03

    Germany, France eye new partners for next-gen tank in 2024

    23 September 2023 - 20:01

    Bob Menendez had built reputation as Senate’s most unethical

    Opinion by Thomas Anderson

    23 September 2023 - 19:00

    Azerbaijan sends 24 tonnes of petrol and 40 tonnes of diesel fuel to Garabagh Armenians

    23 September 2023 - 18:17

    President Ilham Aliyev receives European Union Special Representative for South Caucasus

    23 September 2023 - 18:05

    PM: Azerbaijan's strategic foreign exchange reserves hit $67 billion

    23 September 2023 - 18:00

    World Championship: Azerbaijani wrestler reaches semifinal

    23 September 2023 - 17:49

    South Africa plans to open consulate in Azerbaijan

    23 September 2023 - 17:38

    Armenian-left ammunition depot discovered in Kalbajar

    23 September 2023 - 17:24

    Azerbaijan's Azykh and Taglar caves inscribed on UNESCO World Heritage List

    23 September 2023 - 17:18

    Russia does not directly attack Romania, president says

    23 September 2023 - 17:07

    US approves $500 million sale for Saudi Arabia’s combat vehicle upkeep

    23 September 2023 - 16:55

    Russia still 'occupies 20% of our territory': Georgian PM

    23 September 2023 - 16:43

    Taiwan moves closer to acquiring 160 Turkish-made Jackal drones

    PHOTO

    23 September 2023 - 16:32

    FM: Once Garabagh Armenians get rid of criminal junta regime, wide opportunities will open up for them

    23 September 2023 - 16:29

    Azerbaijan sends fuel to Khankendi

    PHOTO

    23 September 2023 - 16:24

    President Ilham Aliyev offers condolences to President of Italy

    23 September 2023 - 16:21

    OTG Secretary General: Garabagh is Azerbaijani land, part of Turkic world

    23 September 2023 - 16:12

    Russian-Hungarian cooperation in space technology will continue - FM

    23 September 2023 - 16:01

    Biden aides in talks with Vietnam for arms deal that could irk China

    23 September 2023 - 15:50

    Artur Aghajanov: Future of Garabagh is connected with Azerbaijan

    23 September 2023 - 15:39

    Armenian daily: Pashinyan ordered crackdown on protests

    23 September 2023 - 15:28

    Information campaign on Armenian mine terror held in London and Manchester

    PHOTO

    23 September 2023 - 15:18

    Quake jolts Türkiye

    23 September 2023 - 15:17

    Cash, gold and a luxury car

    The eye-popping allegations against Bob Menendez

    23 September 2023 - 15:05

    Azerbaijan expects Armenians to fully honour obligations – roving ambassador

    23 September 2023 - 14:53

    Armenian tank shot down in Shusha by Albert Agharunov delivered to Baku

    PHOTO

    23 September 2023 - 14:41

    Netanyahu says Israel is getting closer to "quantum leap" normalisation deal with Saudi Arabia

    23 September 2023 - 14:30

    Pakistani PM: Adding more permanent members to UNSC to undermine its authority

    23 September 2023 - 14:19

All news