Supply Chain Incident

3CX desktop application software supply-chain compromise

Attackers compromised 3CX desktop application builds, causing trojanized installers and updates to reach downstream customers.

ConfidenceHigh
Evidence LevelResearcher
Attack StageBuild Compromise
Source Artifact DivergenceUnknown
Attribution ConfidenceLikely

Executive Summary

Timeline

  1. Trojanized desktop application activity precedes disclosure

    The corpus records first observed activity before the public disclosure date and models the distribution through signed desktop application channels.

  2. Mandiant publishes detailed supply-chain analysis

    Mandiant's report is the researcher reference used for the structured build-compromise and signed-update modeling in this record.

Attack Chain

  1. Vendor build compromise

    The compromise is represented at the 3CX DesktopApp build pipeline rather than as a package-registry event.

  2. Signed desktop application distribution

    Trojanized artifacts reached users through signed software installer and update paths recorded in the distribution-channel field.

  3. Downstream customer exposure

    The impact categories include malware distribution, backdoor behavior, and downstream customer compromise through trusted application delivery.

Affected Ecosystem

Defensive Lessons

Detection Notes

Open Questions

Affected Packages

No structured records.

Affected Releases

No structured records.

Repositories

No structured records.

Organizations

Maintainers

No structured records.

Threat Actors

Campaigns

Build Systems

  • 3CX DesktopApp build pipeline

Distribution Channels

  • Signed software installer/update channel

Compromised Accounts

No structured records.

Connected Entities

Attribution Evidence

References