logo

A Comprehensive Analysis of the 3CX Attack

ID: 5bc6a24f-4a3f-58aa-a091-41e2a52c1656

STIX ID: report--5bc6a24f-4a3f-58aa-a091-41e2a52c1656

Feed Name: Cyble Blog

Threat Score
90/100

Date Published: 2025-12-16

Date Updated: 2026-07-16

...
...

A widespread supply-chain compromise of the 3CX DesktopApp delivered a digitally signed Trojanized installer (Windows and macOS) that drops malicious DLLs (ffmpeg.dll and d3dcompiler_47.dll). The ffmpeg DLL decrypts embedded shellcode via RC4 which loads an embedded DLL that waits seven days, retrieves Base64 + AES-GCM encrypted C2 URLs from ICO files in a GitHub repo, and downloads a final stealer capable of harvesting system information and browser credentials; the campaign affected a large installed base (3CX claims ~600,000 companies / 12M daily users) and includes numerous IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.