IconicStealer
- First seen
- 2023-03-30 00:00:00
- Malware type
- credential-stealer, spyware
- Last IoC activity
- 2026-05-22 22:01:11
- Profile updated
- 2026-07-07 13:10:48
Targeted industries: technology-and-telecommunications
Context
Follow-up payload in 3CX supply chain incident, which according to Volexity is an infostealer collecting information about the system and browser using an embedded copy of the SQLite3 library.
Detection coverage
- 2 YARA rules
Detection rules
- VOLEXITY_Apt_Win_Iconicstealer (yara-rule)
- ESET_Richheaders_Lazarus_Nukesped_Iconicpayloads_3CX_Q12023 (yara-rule)
Reports & references
- Mandiant — 3Cx Software Supply Chain Compromise (report)
- ESET — Linux Malware Strengthens Links Lazarus 3Cx Supply Chain Attack (report)
- Broadcom/Symantec — 3Cx Supply Chain Attack (report)
- Trend Micro — Information On Attacks Involving 3Cx Desktop App (report)
- volexity.com — 3Cx Supply Chain Compromise Leads To Iconic Incident (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Iconic Stealer (report)