ThreatPaper
Weak Evidence

The 3CX attackers were linked to the North Korean group APT43

Assessment

Mandiant identified shared IP infrastructure between UNC4736, the cluster responsible for the 3CX and X_TRADER compromises, and two clusters associated with APT43 — UNC3782 and UNC4469 — across three addresses: 89.45.67.160, 172.93.201.88 and 185.38.151.11. Mandiant characterised that overlap as weak, in its own words, and the published DNS resolutions show why. The domains sharing each address resolved weeks or months apart: 172.93.201.88 was used by an UNC3782 domain in November 2021 and by an UNC4736 domain in April 2022; 185.38.151.11 by UNC4736 in January 2023 and by UNC4469 in March 2023. Shared hosting among North Korean clusters is common and does not establish that the same operators were involved. The link is reported downstream without the qualifier that Mandiant attached to it. That is the flattening this rating records: the observation is real and worth reporting, but Mandiant's assessment of its strength is part of the finding, not an optional footnote to it.

Where this claim appeared

BleepingComputer · 2023-04-20

https://www.bleepingcomputer.com/news/security/3cx-hack-caused-by-trading-software-supply-chain-attack/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software Compromise

Think this assessment is wrong? Report an error.