{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:05.735Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"3CX supply chain attack began with a trojanised X_TRADER installer on staff PC","date":"2023-03-29","date_precision":"day","victim_org":"3CX Ltd.","sector":"Technology","country":"Cyprus","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Supply Chain Compromise","Espionage","Credential Theft"],"loss_usd":null,"loss_note":"No loss figure published; 3CX said it had over 600,000 customer companies, though only a subset installed the trojanised builds.","records_affected":null,"threat_actor":"UNC4736 / Lazarus-linked North Korean cluster (Mandiant attribution)","summary":"In late March 2023 3CX's Windows and macOS desktop softphone clients were found to have been trojanised and distributed to customers as signed updates. Mandiant's investigation, published by 3CX on 20 April 2023, concluded the intrusion started when a 3CX employee downloaded and ran a trojanised installer for the X_TRADER trading application, itself the product of an earlier compromise of Trading Technologies' distribution site, on a personal computer. Stolen corporate credentials were then used to reach 3CX's build environment.","how_it_worked":"The employee retrieved what appeared to be a legitimate, digitally signed X_TRADER installer from the vendor's website in 2022. The package carried the VEILEDSIGNAL backdoor, giving the attackers a foothold and the employee's 3CX corporate credentials. Using those credentials the intruders moved into 3CX's network, reached the Windows and macOS build systems, and inserted malicious code into the desktop app build pipeline so that shipped, code-signed updates carried a downloader. Affected customer installations fetched encrypted payloads hidden in icon files on GitHub and, for a small number of selected targets, received a second-stage infostealer. Some reporting has also referred to fake-recruiter lures against 3CX staff, but the confirmed initial vector is the trojanised installer.","lessons":"Build systems should be reachable only from hardened, managed workstations with no personal software installation, and installers from any vendor should be validated against a known-good hash and detonated before use.","confidence":"Confirmed","sources":[{"title":"3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise","url":"https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise","publisher":"Mandiant / Google Cloud"},{"title":"3CX Breach Was a Double Supply Chain Compromise","url":"https://krebsonsecurity.com/2023/04/3cx-breach-was-a-double-supply-chain-compromise/","publisher":"Krebs on Security"},{"title":"Security Update 20 April 2023 - Initial Intrusion Vector Found","url":"https://www.3cx.com/blog/news/mandiant-security-update2/","publisher":"3CX"}],"entry_type":"incident","slug":"2023-3cx-supply-chain-attack-began-with-a-trojanised-x-trader-installer-on-st","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-3cx-supply-chain-attack-began-with-a-trojanised-x-trader-installer-on-st"}]}