logo

3CX supply chain attack analysis

ID: 27c8dc09-1ca2-5488-915b-1b77d9757bbe

STIX ID: report--27c8dc09-1ca2-5488-915b-1b77d9757bbe

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Executive summary: The report analyzes a supply-chain malware campaign that trojanized a signed 3CX Desktop App MSI (3CXDesktopApp-18.12.416.msi). The malicious ffmpeg.dll is side-loaded, locates an MS-signed d3dcompiler_47.dll containing RC4-encrypted shellcode (key: "3jB(2bsG#@c7"), decrypts and executes a second-stage DLL which downloads icon files from GitHub, extracts and decrypts a C2 URL (https://glcloudservice.com/v1/console), and eventually deploys an infostealer capable of harvesting saved browser credentials and system information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.