3CX DesktopApp Supply Chain Attack
The 3CX supply chain attack involved the distribution of trojanized software updates to facilitate unauthorized network access and potential data exfiltration.
CVE search metadata
CVE search record: CVE-2023-29059. Severity: high. CVSS: 7.8. EPSS: 4.37%. KEV: no. Product: 3CXDesktopApp. Brief: 3CX DesktopApp Supply Chain Attack. Brief link: https://feed.craftedsignal.io/briefs/2026-10-3cx-supply-chain/
In early 2023, the 3CX desktop application was compromised as part of a significant software supply chain attack. Threat actors successfully injected malicious code into signed 3CXDesktopApp updates, which were then distributed to customers globally through the official vendor update mechanism. This technique allowed attackers to achieve initial access to a large number of downstream enterprise networks by exploiting the trust associated with legitimate signed binaries. The malicious updates enabled the deployment of secondary payloads, leading to potential unauthorized network access, internal reconnaissance, and data exfiltration. Defenders must monitor for DNS beacons and anomalous network activity associated with the infrastructure used by this campaign, as established in CVE-2023-29059. The scope of targeting included organizations globally that relied on the affected 3CX communication software.
Attack Chain
- Attackers compromise the build environment or update infrastructure used by 3CX.
- Trojanized, digitally signed versions of the 3CXDesktopApp are published to the official update servers.
- Targets install or receive an automatic update of the compromised 3CXDesktopApp software.
- The malicious code within the application executes, initiating communication with hardcoded C2 domains.
- The primary payload retrieves secondary malicious modules from attacker-controlled external infrastructure.
- The second-stage malware facilitates internal network reconnaissance and credential harvesting.
- Attackers establish persistence and begin exfiltrating sensitive internal data to external C2 nodes.
Impact
The supply chain attack compromised numerous organizations across multiple sectors, leveraging the widespread use of 3CX communication platforms. Successful exploitation allowed attackers to bypass perimeter security controls, establish long-term persistence in corporate environments, and perform unauthorized data exfiltration, representing a critical risk to organizational confidentiality and integrity.
Recommendation
- Monitor DNS query logs for connections to known malicious infrastructure associated with the 3CX campaign, utilizing the domain lookup provided by your threat intelligence platform.
- Implement detection for unauthorized network communication from the 3CXDesktopApp process (Sysmon Event ID 22 or equivalent DNS logs).
- Ensure all instances of 3CXDesktopApp are updated to the latest vendor-provided versions to mitigate CVE-2023-29059.
- Perform retrospective hunting in DNS and proxy logs for any communication with infrastructure associated with the 3CX actor starting from early 2023.
Immediate actions
Audit environment for existence of 3CXDesktopApp and ensure versions are patched.
Threat Hunt
DNS queries from endpoints to domains associated with 3CX infrastructure.
Data: Sysmon Event ID 22