Skip to main content
Skip to main content
Published Apr 01, 2023 | Updated Dec 20, 2023

Trojan:Script/SamScissors.C!ico

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

This is a detection for the trojan, SamScissors. SamScissors is associated with command-and-control (C2) communications involving possible 3CXDesktopApp supply chain compromise.

This threat has been observed in the activities by the group Citrine Sleet (DEV-1039), a threat actor based in North Korea that performs financially motivated attacks.

3CX users should install updates on self-hosted and on-premise servers and uninstall affected desktop clients to mitigate the threat. Users can also consider using the web client version (PWA).

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us