3CX’s Software Supply Chain Compromise: Lessons Learned
ID: e7ebadd5-e704-5c8e-a7f7-6fd68b1f5c28
STIX ID: report--e7ebadd5-e704-5c8e-a7f7-6fd68b1f5c28
Feed Name: ReversingLabs Blog
In March 2023 the 3CXDesktopApp was compromised via the vendor's development pipeline, with attackers (attributed to North Korea's Lazarus Group) appending RC4-encrypted shellcode to a d3dcompiler.dll and modifying ffmpeg to execute it; the incident affected many customers and targeted select cryptocurrency-related victims. Post-incident, 3CX engaged Mandiant and ReversingLabs, implemented comprehensive CI/CD and supply-chain security controls (binary analysis, SAST, bug bounty, SBOMs), and now uses those measures to assert greater software transparency and integrity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
