Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationNo AI reportedConfirmed

3CX supply chain attack began with a trojanised X_TRADER installer on staff PC

3CX Ltd. · Technology · Cyprus · March 29, 2023

What happened

In late March 2023 3CX's Windows and macOS desktop softphone clients were found to have been trojanised and distributed to customers as signed updates. Mandiant's investigation, published by 3CX on 20 April 2023, concluded the intrusion started when a 3CX employee downloaded and ran a trojanised installer for the X_TRADER trading application, itself the product of an earlier compromise of Trading Technologies' distribution site, on a personal computer. Stolen corporate credentials were then used to reach 3CX's build environment.

How the deception worked

The employee retrieved what appeared to be a legitimate, digitally signed X_TRADER installer from the vendor's website in 2022. The package carried the VEILEDSIGNAL backdoor, giving the attackers a foothold and the employee's 3CX corporate credentials. Using those credentials the intruders moved into 3CX's network, reached the Windows and macOS build systems, and inserted malicious code into the desktop app build pipeline so that shipped, code-signed updates carried a downloader. Affected customer installations fetched encrypted payloads hidden in icon files on GitHub and, for a small number of selected targets, received a second-stage infostealer. Some reporting has also referred to fake-recruiter lures against 3CX staff, but the confirmed initial vector is the trojanised installer.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Build systems should be reachable only from hardened, managed workstations with no personal software installation, and installers from any vendor should be validated against a known-good hash and detonated before use.

Sources (3)

  1. 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise
    Mandiant / Google Cloud·cloud.google.comOpen ↗
  2. 3CX Breach Was a Double Supply Chain Compromise
    Krebs on Security·krebsonsecurity.comOpen ↗
  3. Security Update 20 April 2023 - Initial Intrusion Vector Found
    3CX·3cx.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.