There is a malware variant out there known as ICONICSTEALER, which ended up used in the supply chain attack on the commercial software 3CXDesktopApp. The primary purpose of this malware is to steal sensitive data from a victim user’s web browser, and make it available for exfiltration by a separate malicious component.

To that end, CISA released a Malware Analysis Report (MAR) on the infostealer. In the report, CISA experts discuss in detail one file from ICONICSTEALER.

This file is a 64-bit Windows DLL (Dynamic-link Library). Analysis indicates this application was part of a supply chain attack against the commercial application 3CXDesktopApp. This malicious DLL was within an installer for the 3CXDesktopApp.

The primary purpose of this DLL is to steal information from various web browsers employed by a victim user. During runtime the application first attempts to read a file named “\\3CXDesktopApp\\config.json”. Additionally, the malware attempts to collect the victim system’s hostname, domain name, and OS version.

The malicious application next attempts to steal sensitive information from the victim user’s web browser. Specifically it will target the Chrome, Edge, Brave, or Firefox browsers. It uses an embedded SQLITE library to query the browser databases for sensitive information. Analysis indicates the data stolen from the web browsers will be websites recently visited including sensitive parameters passed to the sites. These parameters could include sensitive information including login credentials or credit card numbers.

Schneider Bold

No exfiltration capability was discovered within this malicious application, indicating it works with another malicious component to exfiltrate collected data.

Click here for more on the report.

CISA recommends users and administrators consider using the following best practices to strengthen the security posture of their organization’s systems:

  • Maintain up-to-date antivirus signatures and engines.
  • Keep operating system patches up-to-date.
  • Disable File and Printer sharing services. If these services are required, use strong passwords or Active Directory authentication.
  • Restrict users’ ability (permissions) to install and run unwanted software applications. Do not add users to the local administrators group unless required.
  • Enforce a strong password policy and implement regular password changes.
  • Exercise caution when opening e-mail attachments even if the attachment is expected and the sender appears to be known.
  • Enable a personal firewall on agency workstations, configured to deny unsolicited connection requests.
  • Disable unnecessary services on agency workstations and servers.
  • Scan for and remove suspicious e-mail attachments; ensure the scanned attachment is its “true file type” (i.e., the extension matches the file header).
  • Monitor users’ web browsing habits; restrict access to sites with unfavorable content.
  • Exercise caution when using removable media (e.g., USB thumb drives, external drives, CDs, etc.).
  • Scan all software downloaded from the Internet prior to executing.
  • Maintain situational awareness of the latest threats and implement appropriate Access Control Lists (ACLs).
ISSSource

Pin It on Pinterest

Share This