ICONICSTEALER is an information-stealing malware payload used in the 3CX software supply-chain compromise affecting trojanized Windows and macOS 3CX Desktop applications. Reporting describes it as a later-stage payload delivered after the malicious 3CX update chain, in which trojanized ffmpeg libraries were used to decode configuration data and retrieve additional payloads from attacker-controlled infrastructure. Volexity referred to the initial loader as ICONIC and the Windows second-stage stealer as ICONICSTEALER; other reporting also describes it as a third-stage password-stealing program. The malware has been linked by multiple vendors to Lazarus / LABYRINTH CHOLLIMA, with Volexity later attributing the activity to Lazarus based on shellcode overlap with APPLEJEUS.
On Windows, ICONIC downloaded encrypted configuration data hidden in GitHub-hosted ICO files from github[.]com/IconStorages/images/, decrypted the data with AES-GCM, and used the resulting URLs to retrieve the next-stage payload. Retrieval of the Windows payload required a cookie header of the form __tutma={MachineGuid}, where MachineGuid was derived from SOFTWARE\Microsoft\Cryptography; without the cookie, servers returned HTTP 204. Volexity reported the returned content consisted of shellcode followed by a 64-bit DLL identified as ICONICSTEALER. The attacker infrastructure appeared to proxy requests to upstream C2, and a given MachineGuid cookie reportedly worked only once across different C2s.
Volexity reported ICONICSTEALER was compiled on March 16, 2023 and used an embedded SQLite3 library to collect host and browser information. Specifically, it collected hostname, domain name, OS version, and browser history entries (title and URL) from Brave, Chrome, Edge, and Firefox, limited to the first 500 entries, then POSTed the data back to C2. Other reporting states AppleJeus leveraged ICONICSTEALER to steal browser information, including browser history, from infected hosts. Mandiant also described the final payload as a password-stealing program dubbed ICONICSTEALER.
The malware was delivered through malicious 3CX installers signed by 3CX and distributed via 3CX infrastructure, impacting both Windows and macOS customers. The broader 3CX compromise affected organizations across industries using 3CX software. High-confidence related artifacts in reporting include the malicious Windows installer 3CXDesktopApp-18.12.416.msi (MD5: 0eeb1c0133eb4d571178b2d9d14ce3e9; SHA256: 59e1edf4d82fae4978e97512b0331b7eb21dd4b838b850ba46794d9c7a2c0983), malicious ffmpeg.dll (MD5: 74bc2d0b6680faa1a5a76b27e5479cbc; SHA256: 7986bbaee8940da11ce089383521ab420c443ab7b15ed42aed91fd31ce833896), and GitHub-hosted icon[0-15].ico files used as dead-drop resolvers for C2 discovery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AppleJeus leveraged ICONICSTEALER to steal browser information to include browser history located on the infected host.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows second-stage payload retrieved by IconicLoader in the 3CX supply-chain incident; described as a payload family paired with IconicLoader and associated with Lazarus-attributed activity in the report.
A third-stage payload in the 3CX supply-chain compromise chain; it is described as a password-stealing program retrieved after earlier stages resolve C2 details via encrypted icon files hosted on GitHub.
Information-stealing malware used to collect browser data such as history from infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.