WHOIS API
Chat Applications Exploited in Supply Chain Attacks
Pages
17
Time to read
13 mins
Language
English
Pages
17
Time to read
13 mins
Language
English
This technical report outlines the exploitation of chat applications, specifically Comm100 and LiveHelp100, by threat actors to initiate supply chain attacks. The report details the indicators of compromise (IoCs) identified by Trend Micro, including specific command-and-control (C&C) server addresses. Additionally, it presents findings from an analysis conducted by WhoisXML API researchers, which expanded the list of IoCs through extensive IP, DNS, and WHOIS intelligence. The analysis revealed nine additional IP addresses and numerous domains associated with the C&C servers. The report also discusses the potential risks posed to other chat applications and their users, highlighting the need for vigilance against similar threats. The findings indicate that a significant number of domains related to popular chat apps were identified, with a small percentage attributed to legitimate companies. The report concludes with a call for organizations to be aware of the malicious domains identified in the study.