ThreatPaper
Superseded

The 3CX macOS build server was compromised with the SIMPLESEA backdoor

Assessment

Mandiant's initial findings, published through 3CX on 11 April 2023, identified a macOS backdoor named SIMPLESEA on the compromised build server, located at /Library/Graphics/Quartz with MD5 d9d19abffc2c7dac11a16745f4aea44f. The report described its supported commands as shell execution, file transfer, file execution, file management and configuration updating, and noted a configuration file at /private/etc/apdl.cf single-byte XOR encoded with key 0x5e. Nine days later, on 20 April 2023, Mandiant Intelligence analysed the sample again and found a high degree of code overlap with POOLRAT, a previously known macOS backdoor. Mandiant deprecated SIMPLESEA in favour of POOLRAT. The claim was accurate as published and was corrected by the source that made it. It is recorded here because a substantial volume of secondary coverage still names SIMPLESEA, having been written in the window between the two reports and never revisited — which is the ordinary way a superseded finding outlives its correction.

Where this claim appeared

3CX · 2023-04-11

https://www.3cx.com/blog/news/mandiant-initial-results/

What “Superseded” means

Reported accurately at the time, then corrected by the original source. Recorded because the original version usually continues circulating long after the correction.

2 of 5 · rating scale

Assessed in

3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software Compromise

Think this assessment is wrong? Report an error.