<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:3cx:3cx:18.12.407:*:*:*:*:windows:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3a3cx3cx18.12.407windows/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 12:30:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3a3cx3cx18.12.407windows/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>3CX DesktopApp Supply Chain Attack</title><link>https://feed.craftedsignal.io/briefs/2026-10-3cx-supply-chain/</link><pubDate>Mon, 05 Oct 2026 12:30:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-3cx-supply-chain/</guid><description>The 3CX supply chain attack involved the distribution of trojanized software updates to facilitate unauthorized network access and potential data exfiltration.</description><content:encoded><![CDATA[<p>In early 2023, the 3CX desktop application was compromised as part of a significant software supply chain attack. Threat actors successfully injected malicious code into signed 3CXDesktopApp updates, which were then distributed to customers globally through the official vendor update mechanism. This technique allowed attackers to achieve initial access to a large number of downstream enterprise networks by exploiting the trust associated with legitimate signed binaries. The malicious updates enabled the deployment of secondary payloads, leading to potential unauthorized network access, internal reconnaissance, and data exfiltration. Defenders must monitor for DNS beacons and anomalous network activity associated with the infrastructure used by this campaign, as established in CVE-2023-29059. The scope of targeting included organizations globally that relied on the affected 3CX communication software.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attackers compromise the build environment or update infrastructure used by 3CX.</li>
<li>Trojanized, digitally signed versions of the 3CXDesktopApp are published to the official update servers.</li>
<li>Targets install or receive an automatic update of the compromised 3CXDesktopApp software.</li>
<li>The malicious code within the application executes, initiating communication with hardcoded C2 domains.</li>
<li>The primary payload retrieves secondary malicious modules from attacker-controlled external infrastructure.</li>
<li>The second-stage malware facilitates internal network reconnaissance and credential harvesting.</li>
<li>Attackers establish persistence and begin exfiltrating sensitive internal data to external C2 nodes.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The supply chain attack compromised numerous organizations across multiple sectors, leveraging the widespread use of 3CX communication platforms. Successful exploitation allowed attackers to bypass perimeter security controls, establish long-term persistence in corporate environments, and perform unauthorized data exfiltration, representing a critical risk to organizational confidentiality and integrity.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Monitor DNS query logs for connections to known malicious infrastructure associated with the 3CX campaign, utilizing the domain lookup provided by your threat intelligence platform.</li>
<li>Implement detection for unauthorized network communication from the 3CXDesktopApp process (Sysmon Event ID 22 or equivalent DNS logs).</li>
<li>Ensure all instances of 3CXDesktopApp are updated to the latest vendor-provided versions to mitigate CVE-2023-29059.</li>
<li>Perform retrospective hunting in DNS and proxy logs for any communication with infrastructure associated with the 3CX actor starting from early 2023.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>trojan</category><category>3cx</category></item></channel></rss>