3CX VoIP Software Compromise & Supply Chain Threats
ID: 5cbcc152-e22d-542f-a980-2ebcd0837ef1
STIX ID: report--5cbcc152-e22d-542f-a980-2ebcd0837ef1
Feed Name: Huntress Blog
Threat Score
**Executive summary:** The 3CX DesktopApp was compromised and signed updates delivered a backdoored ffmpeg.dll which loads an encrypted d3dcompiler_47.dll and subsequent payloads that sleep and then contact GitHub-hosted C2 endpoints; Huntress provides IOCs (SHA256 hashes, domains), detection guidance (YARA, process lineage) and a PowerShell checking script, and notes suspected DPRK-linked attribution and broad potential impact across hundreds of thousands of 3CX installations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
