#LabyrinthChollima #GOLDENCHOLLIMA #PRESSURECHOLLIMA
https://www.crowdstrike.com/en-us/blog/labyrinth-chollima-evolves-into-three-adversaries/
CrowdStrike and SentinelOne are reporting that a version of the 3CX softphone app has been bundled with malware in a supply chain attack, similar to what happened with Solarwinds. CrowdStrike intelligence has attributed this activity to a North Korean APT group they track as LABYRINTH CHOLLIMA. The response from 3CX is arrogant as hell!
#InfoSec #3CX #SupplyChainAttack #CrowdStrike #SentinelOne #NorthKorea #DPRK #APT #LABYRINTHCHOLLIMA
Anybody tracking the 3CX Desktop App incident? @crowdstrike is reporting a potential software supply chain compromise by Lazarus Group.