Security alert: 3CXDesktopApp supply chain attack
ID: fa1ccc8a-d00c-52b9-bb42-796801062240
STIX ID: report--fa1ccc8a-d00c-52b9-bb42-796801062240
Feed Name: Expel Blog
3CX's desktop application (3CXDesktopApp) was compromised in a supply-chain attack that trojanized official installers for Windows and macOS (multiple specific versions listed), enabling multi-stage malicious activity; CrowdStrike confirmed the compromise and EDR vendors observed quarantines beginning March 22, 2023. The report highlights the broad potential impact given 3CX's large user base, recommends immediate mitigations (use the PWA instead of the desktop app, apply updates, block known IOCs), and describes monitoring and detection actions taken by responders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
