X_TRADER software delivered VEILEDSIGNAL backdoor
A compromised installer for the retired X_TRADER financial software, available on Trading Technologies' official website and signed with their certificate, contained the VEILEDSIGNAL backdoor.
Story
X_TRADER was retired software that still sat on an official download path. In 2022, Trading Technologies' site served X_TRADER_r7.17.90p608.exe, signed by Trading Technologies International, Inc., even though the platform had reportedly been discontinued in 2020.
The installer executed Setup.exe. That program dropped two trojanized DLLs and a benign executable, then used DLL side-loading to run the malicious code. SIGFLIP located shellcode using the FEEDFACE marker and an RC4 configuration, DAVESHELL loaded the payload in memory, and the final implant was VEILEDSIGNAL.
VEILEDSIGNAL was a modular backdoor. It could send implant data, execute shellcode, and terminate itself. Its communication module used a named pipe and encrypted traffic with AES-256-GCM; its configured URL reused a Trading Technologies-looking path, www.tradingtechnologies.com/trading/order-management.
The impact was larger than the X_TRADER user base. Mandiant found that a 3CX employee installed the trojanized X_TRADER package on a personal machine, the actor stole corporate credentials, and the access later led to compromise of 3CX's build environments. This was a supply-chain attack that became another supply-chain attack.
Affected Artifacts
- Observed
- 2021-11-01 to 2022-07-26
- Compromised Versions
- Unknown
- Fixed
- Not listed
- Hashes
-
- md5:ef4ab22e565684424b4142b1294f1f4d
- sha1:ced671856bbaef2f1878a2469fb44e9be8c20055
- sha256:fbc50755913de619fb830fb95882e9703dbfda67dbd0f75bc17eadc9eda61370
- +5 more
- Evidence
- distribution: tradingtechnologies.com/x-trader/downloads/X_TRADER_r7.17.90p608.exe, distribution: tradingtechnologies.com/legacy-downloads/X_TRADER%20Pro%207.17.10.exe, distribution: downloads.tradingtechnologies.com/trading-software/x-trader/legacy/setup.exe, mirror: virustotal.com/gui/file/ef4ab22e565684424b4142b1294f1f4d , +10 more
- Affected X_TRADER scope covered installer versions available from November 2021 through July 2022, including X_TRADER_r7.17.90p608.exe reporting.
- Mandiant identified this installer as the initial intrusion vector that led to the later 3CX build-environment compromise.
Incident Context
- Motive
- Financial Gain
- Attribution
- State
- Cause
- Website Compromise
- Transitive
- No
- Actor
- Nation-state
- User Impact
- 97
External References
- Security Update Thursday 20 April 2023 - Initial Intrusion Vector Found3cx.com
- 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromisecloud.google.com
- Cascading Supply Chain Attack - 3CX Hacked After Employee Downloaded Trojanized Appsecurityweek.com
- 3CX attack traced to X_TRADER supply chain compromisecybersecuritydive.com
- Software maker 3CX was compromised by another supply-chain attackzetter-zeroday.com
Source record: proprietary/x_trader/meta.yaml