Ongoing Active Trojanized 3CX Desktop App Potentially Affecting 600K Users Globally
ID: ffaa1dfa-2108-51a9-89eb-967fddfd474f
STIX ID: report--ffaa1dfa-2108-51a9-89eb-967fddfd474f
Feed Name: CloudSEK Blog
**Executive Summary:** On 29 March 2023 CrowdStrike and other vendors reported a supply-chain compromise of the signed 3CX Desktop Electron application that delivered multi-stage malicious payloads (malicious ffmpeg.dll, appended encrypted payloads in d3dcompiler_47.dll, and an information-stealer retrieved via an embedded Base64 .ico), affecting Windows and macOS users; the report includes timelines, detection guidance, domain and file-hash IOCs, and recommended mitigation to avoid the Electron client until remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
