UTA0040 is a temporary tracking designation used for the threat activity associated with the 2023 compromise of the 3CX Desktop App software supply chain. The operation involved trojanized, legitimately signed Windows and macOS builds of the 3CX desktop client that were distributed through normal update channels. Malicious components embedded in bundled media libraries acted as loaders, decrypted shellcode, and retrieved additional payloads from attacker-controlled infrastructure. Researchers referred to the initial loader as ICONIC and the second-stage information stealer as ICONICSTEALER. On Windows, the compromised application used a malicious library-loading chain to decode and execute shellcode, delay execution, retrieve encrypted configuration data from attacker-controlled content hosted on GitHub, and contact command-and-control infrastructure for follow-on payload delivery. The second stage collected host information and browser history and exfiltrated the results, indicating clear information-theft and post-compromise collection objectives. The malware also used selective delivery logic, including cookie-based request requirements and infrastructure behavior consistent with victim filtering and staged payloading. On macOS, a trojanized library contained an obfuscated embedded server list and similar logic for contacting command-and-control infrastructure and requesting next-stage content. The campaign is notable as a software supply-chain intrusion affecting both Windows and macOS users of a widely deployed enterprise communications product. Observed behaviors include initial access through trusted software distribution, defense evasion through signed software and delayed execution, in-memory payload execution, process-context execution, and data exfiltration. Public reporting initially stated that the activity could not be mapped with confidence to a known actor and therefore tracked it as UTA0040. Subsequent assessment linked the operation to Lazarus, also known as LABYRINTH CHOLLIMA, based on malware and shellcode overlaps with APPLEJEUS. Because UTA0040 originated as an unmapped temporary cluster name, it is best understood as the designation for the actor behind the 3CX supply-chain operation before later attribution updates.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
105 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.