{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3a3cx3cx18.11.1213macos/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:3cx:3cx:18.11.1213:*:*:*:*:macos:*:*","cpe:2.3:a:3cx:3cx:18.12.402:*:*:*:*:macos:*:*","cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:macos:*:*","cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:windows:*:*","cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:macos:*:*","cpe:2.3:a:3cx:3cx:18.12.416:*:*:*:*:windows:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2023-29059"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["3CXDesktopApp"],"_cs_severities":["high"],"_cs_tags":["supply-chain","trojan","3cx"],"_cs_type":"advisory","_cs_vendors":["3CX"],"content_html":"\u003cp\u003eIn early 2023, the 3CX desktop application was compromised as part of a significant software supply chain attack. Threat actors successfully injected malicious code into signed 3CXDesktopApp updates, which were then distributed to customers globally through the official vendor update mechanism. This technique allowed attackers to achieve initial access to a large number of downstream enterprise networks by exploiting the trust associated with legitimate signed binaries. The malicious updates enabled the deployment of secondary payloads, leading to potential unauthorized network access, internal reconnaissance, and data exfiltration. Defenders must monitor for DNS beacons and anomalous network activity associated with the infrastructure used by this campaign, as established in CVE-2023-29059. The scope of targeting included organizations globally that relied on the affected 3CX communication software.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttackers compromise the build environment or update infrastructure used by 3CX.\u003c/li\u003e\n\u003cli\u003eTrojanized, digitally signed versions of the 3CXDesktopApp are published to the official update servers.\u003c/li\u003e\n\u003cli\u003eTargets install or receive an automatic update of the compromised 3CXDesktopApp software.\u003c/li\u003e\n\u003cli\u003eThe malicious code within the application executes, initiating communication with hardcoded C2 domains.\u003c/li\u003e\n\u003cli\u003eThe primary payload retrieves secondary malicious modules from attacker-controlled external infrastructure.\u003c/li\u003e\n\u003cli\u003eThe second-stage malware facilitates internal network reconnaissance and credential harvesting.\u003c/li\u003e\n\u003cli\u003eAttackers establish persistence and begin exfiltrating sensitive internal data to external C2 nodes.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe supply chain attack compromised numerous organizations across multiple sectors, leveraging the widespread use of 3CX communication platforms. Successful exploitation allowed attackers to bypass perimeter security controls, establish long-term persistence in corporate environments, and perform unauthorized data exfiltration, representing a critical risk to organizational confidentiality and integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMonitor DNS query logs for connections to known malicious infrastructure associated with the 3CX campaign, utilizing the domain lookup provided by your threat intelligence platform.\u003c/li\u003e\n\u003cli\u003eImplement detection for unauthorized network communication from the 3CXDesktopApp process (Sysmon Event ID 22 or equivalent DNS logs).\u003c/li\u003e\n\u003cli\u003eEnsure all instances of 3CXDesktopApp are updated to the latest vendor-provided versions to mitigate CVE-2023-29059.\u003c/li\u003e\n\u003cli\u003ePerform retrospective hunting in DNS and proxy logs for any communication with infrastructure associated with the 3CX actor starting from early 2023.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-05T12:30:24Z","date_published":"2026-10-05T12:30:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-3cx-supply-chain/","summary":"The 3CX supply chain attack involved the distribution of trojanized software updates to facilitate unauthorized network access and potential data exfiltration.","title":"3CX DesktopApp Supply Chain Attack","url":"https://feed.craftedsignal.io/briefs/2026-10-3cx-supply-chain/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:3cx:3cx:18.11.1213:*:*:*:*:macos:*:*","version":"https://jsonfeed.org/version/1.1"}