Mar 31, 2023
D3dcompiler_47.dll: If AV raises an alerts about this Microsoft signed dll file, you are in trouble
Posted by Saúl Morales Rodriguéz in categories: cybercrime/malcode, encryption, internet
Threat actors used a well-liked piece of corporate communication software from 3CX, according to security experts. In particular, reports state that a desktop client for the 3CX VoIP (Voice over Internet Protocol) service was used to specifically target 3CX’s clients.
It is believed that the attack is a multi-part process, with the first stage using a hacked version of the 3CX desktop application. Although the.exe file and the MSI package have the same name, preliminary research indicates that the MSI package is the one that may include DLLs that have been maliciously modified.