Malicious 3CX Second-Stage C2 Icon Retrieval from GitHub IconStorages (via dns_query)

PremiumReviewedSigma · High · v1
Product
windows
Category
dns_query
Author
HuntRule
Published
2026-10-02
Updated
2026-10-02

ATT&CK techniques

Defense Evasion → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects the 3CX desktop application resolving raw.githubusercontent.com, which the second stage contacts to fetch ICO files from the IconStorages repository hiding encoded C2 configuration. This beacon follows a dormancy period and precedes browser credential theft in the supply chain intrusion.

Related detections9 linkedT1071.001 — drag to rearrange
Malicious SesameOp Netapi64 Loader DLL Load via Masqueraded Netapi Module (via image_load)
Suspicious PowerShell Web Request to oastify Out-of-Band Domain
Suspicious AstarionRAT HTTP Beacon Cookie Values
Suspicious osascript Spawning curl to High Port C2 via process_creation
Suspicious PowerShell Spawned by Web Browser
Suspicious Outbound Request to Webhook.site Interaction Service
Malicious C2 Communication via cur1-request User-Agent on macOS
Suspicious Command Execution via ComSpec Environment Variable Obfuscation
Suspicious AdaptixC2 Beacon Status Request by JadeProx TriBack Loader (via proxy)
Malicious 3CX Second-Stage C2 Icon Retrieval from GitHub IconStorages (via dns_query)
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.