"Massive Supply Chain Attack Targets 3CX Users with Trojanized Apps"

1 min read
Source: The Hacker News
"Massive Supply Chain Attack Targets 3CX Users with Trojanized Apps"
Photo: The Hacker News
TL;DR Summary

Enterprise communications software maker 3CX has confirmed that multiple versions of its desktop app for Windows and macOS are affected by a supply chain attack. The attack leveraged a technique called DLL side-loading to load a rogue library referred to as "ffmpeg.dll" that's designed to read encrypted shellcode from another DLL called "d3dcompiler_47.dll." Cybersecurity firm CrowdStrike has attributed the attack with high confidence to Labyrinth Chollima, a North Korea-aligned state-sponsored actor.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

3 min

vs 4 min read

Condensed

89%

67471 words

Want the full story? Read the original article

Read on The Hacker News