logo

3CX’s Software Supply Chain Compromise: Lessons Learned

ID: e7ebadd5-e704-5c8e-a7f7-6fd68b1f5c28

STIX ID: report--e7ebadd5-e704-5c8e-a7f7-6fd68b1f5c28

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2025-07-03

Date Updated: 2026-04-29

Author: [email protected] (Paul Roberts)

...
...

In March 2023 the 3CXDesktopApp was compromised via the vendor's development pipeline, with attackers (attributed to North Korea's Lazarus Group) appending RC4-encrypted shellcode to a d3dcompiler.dll and modifying ffmpeg to execute it; the incident affected many customers and targeted select cryptocurrency-related victims. Post-incident, 3CX engaged Mandiant and ReversingLabs, implemented comprehensive CI/CD and supply-chain security controls (binary analysis, SAST, bug bounty, SBOMs), and now uses those measures to assert greater software transparency and integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.