logo

Recovering from a supply-chain attack: What are the lessons to learn from the 3CX hack?

ID: 369c11be-a4c9-5e67-9db0-abb1dd6f0589

STIX ID: report--369c11be-a4c9-5e67-9db0-abb1dd6f0589

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2023-08-28

Date Updated: 2026-05-01

...
...

The report outlines a multi-stage supply-chain attack where Lazarus-linked actors trojanized a deprecated X_TRADER installer that installed VEILEDSIGNAL malware on a 3CX employee’s personal PC; stolen credentials were then used to compromise 3CX and push information-stealing malware to customers, impacting organizations in the energy and financial sectors and leveraging an optional Windows signature verification vulnerability (CVE-2013-3900). The article also provides defensive recommendations including verified downloads, MFA, privileged access management, patching, and endpoint protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.