Get the app
public
ios_share
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
chevron_right
ISC StormCast for Friday, March 31st, 2023
Mar 31, 2023
06:10
forum
Ask episode
play_arrow
Play
view_agenda
Chapters
auto_awesome
Transcript
info_circle
Episode notes
1
The 3CX Desktop Client Compromise
00:00 • 4min
chevron_right
2
How to Reverse Engineer a PowerShell Script
03:50 • 2min
chevron_right
Malicious 3CX Dekstop App Update
Lifestream (Friday March 31st 1400 ET, 1800 UTC)
https://www.youtube.com/watch?v=cCf3Km_j5bY
3CX Update:
https://www.3cx.com/blog/news/desktopapp-security-alert/
SentinelOne:
https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
Objective-See Blog Post:
https://objective-see.org/blog/blog_0x73.html
Crowdstrike:
https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/
Bypassing PowerShell Strong Obfuscation
https://isc.sans.edu/diary/Bypassing%20PowerShell%20Strong%20Obfuscation/29692