SYMBOLCOMMON_NAMEaka. SYNONYMS
win.iconic_stealer (Back to overview)

IconicStealer

Actor(s): Lazarus Group

VTCollection    

Follow-up payload in 3CX supply chain incident, which according to Volexity is an infostealer collecting information about the system and browser using an embedded copy of the SQLite3 library.

References
2023-04-20 ⋅ Mandiant ⋅ ADRIAN SANCHEZ, DANIEL SCOTT, Dimiter Andonov, Fred Plan, Jake Nicastro, JEFF JOHNSON, Marius Fodoreanu, RENATO FONTANA
3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible
POOLRAT IconicStealer UNC4736
2023-04-20 ⋅ ESET Research ⋅ Marc-Etienne M.Léveillé, Peter Kálnai
Linux malware strengthens links between Lazarus and the 3CX supply‑chain attack
BADCALL SimpleTea POOLRAT 3CX Backdoor BADCALL IconicStealer
2023-03-30 ⋅ Volexity ⋅ Ankur Saini, Callum Roxan, Charlie Gardner, Paul Rascagnères, Steven Adair, Thomas Lancaster
3CX Supply Chain Compromise Leads to ICONIC Incident
3CX Backdoor IconicStealer
2023-03-30 ⋅ Trend Micro ⋅ Trend Micro Research
Developing Story: Information on Attacks Involving 3CX Desktop App
3CX Backdoor IconicStealer
2023-03-30 ⋅ Symantec ⋅ Threat Hunter Team
3CX: Supply Chain Attack Affects Thousands of Users Worldwide
3CX Backdoor IconicStealer
Yara Rules
[TLP:WHITE] win_iconic_stealer_auto (20260917 | Detects win.iconic_stealer.)
rule win_iconic_stealer_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.iconic_stealer."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.iconic_stealer"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { eb32 418d4501 898390000000 4a8d0c6d00000000 498b06 4903cd c704c810000000 }
            // n = 7, score = 100
            //   eb32                 | test                eax, eax
            //   418d4501             | je                  0x106b
            //   898390000000         | dec                 eax
            //   4a8d0c6d00000000     | mov                 ecx, eax
            //   498b06               | dec                 eax
            //   4903cd               | mov                 eax, dword ptr [eax + 0x58]
            //   c704c810000000       | inc                 ecx

        $sequence_1 = { e8???????? eb05 e8???????? 8945e4 8bf8 85c0 0f84a6000000 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   eb05                 | movsx               eax, word ptr [esi + 0x36]
            //   e8????????           |                     
            //   8945e4               | inc                 eax
            //   8bf8                 | dec                 ecx
            //   85c0                 | arpl                ax, bx
            //   0f84a6000000         | inc                 ecx

        $sequence_2 = { c6008a 488b8c24a8000000 4885d2 48895808 488b4160 48894328 488b4160 }
            // n = 7, score = 100
            //   c6008a               | movzx               eax, ax
            //   488b8c24a8000000     | cmp                 ecx, eax
            //   4885d2               | jg                  0x1bb1
            //   48895808             | test                ecx, ecx
            //   488b4160             | xor                 esi, esi
            //   48894328             | dec                 esp
            //   488b4160             | arpl                word ptr [edi + 0x90], bp

        $sequence_3 = { eb04 4883c020 4883c428 c3 66894c2408 4883ec58 b8ffff0000 }
            // n = 7, score = 100
            //   eb04                 | push                ebx
            //   4883c020             | push                ebp
            //   4883c428             | push                esi
            //   c3                   | inc                 ecx
            //   66894c2408           | push                esp
            //   4883ec58             | inc                 ecx
            //   b8ffff0000           | pop                 ebp

        $sequence_4 = { e8???????? 488d4348 c7433420000100 48894310 4533e4 48897b28 897330 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   488d4348             | mov                 byte ptr [ebx + 8], dh
            //   c7433420000100       | inc                 eax
            //   48894310             | mov                 byte ptr [ebx + 0x17], dh
            //   4533e4               | inc                 esp
            //   48897b28             | mov                 byte ptr [ebx + 0x12], ah
            //   897330               | inc                 eax

        $sequence_5 = { 8b5718 85d2 0f84c0000000 83fa65 0f84b7000000 8bca 4c8d05307b0300 }
            // n = 7, score = 100
            //   8b5718               | jne                 0x1a8c
            //   85d2                 | dec                 ecx
            //   0f84c0000000         | mov                 ecx, dword ptr [edi + 0x18]
            //   83fa65               | not                 ebp
            //   0f84b7000000         | dec                 esp
            //   8bca                 | mov                 esi, dword ptr [esp + 0x38]
            //   4c8d05307b0300       | dec                 esp

        $sequence_6 = { e8???????? 4d8b36 4d85f6 75c0 488d8f70020000 e8???????? 488bb730020000 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   4d8b36               | dec                 esp
            //   4d85f6               | lea                 eax, [esp + 0x60]
            //   75c0                 | dec                 ecx
            //   488d8f70020000       | add                 ecx, ebp
            //   e8????????           |                     
            //   488bb730020000       | inc                 ecx

        $sequence_7 = { c644c801fd 8954c810 eb03 8b7dd0 4183fc01 740c 41ff4f44 }
            // n = 7, score = 100
            //   c644c801fd           | lea                 edx, [eax + 0x6c]
            //   8954c810             | cmp                 dword ptr [eax], ecx
            //   eb03                 | jg                  0xe74
            //   8b7dd0               | inc                 ecx
            //   4183fc01             | mov                 ecx, 1
            //   740c                 | mov                 dword ptr [esp + 0x20], ebx
            //   41ff4f44             | inc                 esp

        $sequence_8 = { 498bf5 4d85ff 0f855d010000 488b7c2450 bb00900000 488b07 66855814 }
            // n = 7, score = 100
            //   498bf5               | mov                 dword ptr [ecx + 0x110], eax
            //   4d85ff               | ret                 
            //   0f855d010000         | cmp                 byte ptr [ecx + 0x1b], 0
            //   488b7c2450           | cmp                 dword ptr [ecx + 0x30], 0
            //   bb00900000           | jg                  0x17ef
            //   488b07               | inc                 esi
            //   66855814             | dec                 eax

        $sequence_9 = { f6432820 7554 488d542430 c744243000000000 498bc9 e8???????? 8be8 }
            // n = 7, score = 100
            //   f6432820             | inc                 ecx
            //   7554                 | pop                 esi
            //   488d542430           | inc                 ecx
            //   c744243000000000     | mov                 eax, esp
            //   498bc9               | dec                 eax
            //   e8????????           |                     
            //   8be8                 | mov                 ecx, dword ptr [ebp + 0xa0]

    condition:
        7 of them and filesize < 2401280
}
[TLP:WHITE] win_iconicstealer_w0    (20230331 | Detect the ICONICSTEALER malware family.)
rule win_iconicstealer_w0 {
    meta:
        author = "threatintel@volexity.com"
        date = "2023-03-30"
        description = "Detect the ICONICSTEALER malware family."
        hash1 = "8ab3a5eaaf8c296080fadf56b265194681d7da5da7c02562953a4cb60e147423"
        reference = "https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/"
        memory_suitable = 1
        license = "See license at https://github.com/volexity/threat-intel/blob/main/LICENSE.txt"

        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.iconic_stealer"
        malpedia_version = "20230331"
        malpedia_rule_date = "20230331"
        malpedia_hash = ""
        malpedia_license = ""
        malpedia_sharing = "TLP:WHITE"
        
    strings:
        $str1 = "\\3CXDesktopApp\\config.json" wide
        $str2 = "url, title FROM urls" wide
        $str3 = "url, title FROM moz_places" wide

    condition:
        all of them
}
Download all Yara Rules