Proprietary 2021-11-01 · 267 days ·Backdoor, Remote Access

X_TRADER software delivered VEILEDSIGNAL backdoor

A compromised installer for the retired X_TRADER financial software, available on Trading Technologies' official website and signed with their certificate, contained the VEILEDSIGNAL backdoor.

Story

X_TRADER was retired software that still sat on an official download path. In 2022, Trading Technologies' site served X_TRADER_r7.17.90p608.exe, signed by Trading Technologies International, Inc., even though the platform had reportedly been discontinued in 2020.

The installer executed Setup.exe. That program dropped two trojanized DLLs and a benign executable, then used DLL side-loading to run the malicious code. SIGFLIP located shellcode using the FEEDFACE marker and an RC4 configuration, DAVESHELL loaded the payload in memory, and the final implant was VEILEDSIGNAL.

VEILEDSIGNAL was a modular backdoor. It could send implant data, execute shellcode, and terminate itself. Its communication module used a named pipe and encrypted traffic with AES-256-GCM; its configured URL reused a Trading Technologies-looking path, www.tradingtechnologies.com/trading/order-management.

The impact was larger than the X_TRADER user base. Mandiant found that a 3CX employee installed the trojanized X_TRADER package on a personal machine, the actor stole corporate credentials, and the access later led to compromise of 3CX's build environments. This was a supply-chain attack that became another supply-chain attack.

Affected Artifacts

X_TRADER

· tradingtechnologies.com · Binary Archive
Observed
2021-11-01 to 2022-07-26
Compromised Versions
Unknown
Fixed
Not listed
Hashes
  • md5:ef4ab22e565684424b4142b1294f1f4d
  • sha1:ced671856bbaef2f1878a2469fb44e9be8c20055
  • sha256:fbc50755913de619fb830fb95882e9703dbfda67dbd0f75bc17eadc9eda61370
  • +5 more
  • Affected X_TRADER scope covered installer versions available from November 2021 through July 2022, including X_TRADER_r7.17.90p608.exe reporting.
  • Mandiant identified this installer as the initial intrusion vector that led to the later 3CX build-environment compromise.

Incident Context

Motive
Financial Gain
Attribution
State
Cause
Website Compromise
Transitive
No
Actor
Nation-state
User Impact
97

External References

Source record: proprietary/x_trader/meta.yaml