IconicStealer

First seen
2023-03-30 00:00:00
Malware type
credential-stealer, spyware
Last IoC activity
2026-05-22 22:01:11
Profile updated
2026-07-07 13:10:48

Targeted industries: technology-and-telecommunications

Context

Follow-up payload in 3CX supply chain incident, which according to Volexity is an infostealer collecting information about the system and browser using an embedded copy of the SQLite3 library.

Detection coverage

  • 2 YARA rules

Detection rules

  • VOLEXITY_Apt_Win_Iconicstealer (yara-rule)
  • ESET_Richheaders_Lazarus_Nukesped_Iconicpayloads_3CX_Q12023 (yara-rule)

Reports & references

  • Mandiant — 3Cx Software Supply Chain Compromise (report)
  • ESET — Linux Malware Strengthens Links Lazarus 3Cx Supply Chain Attack (report)
  • Broadcom/Symantec — 3Cx Supply Chain Attack (report)
  • Trend Micro — Information On Attacks Involving 3Cx Desktop App (report)
  • volexity.com — 3Cx Supply Chain Compromise Leads To Iconic Incident (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Iconic Stealer (report)

External references