3CXDesktopApp is the trojanized 3CX desktop softphone client involved in a 2023 supply-chain compromise affecting signed Windows and macOS installers. Reported malicious behavior included beaconing to attacker-controlled infrastructure, retrieval of encoded payloads from public hosting including GitHub raw content, deployment of second-stage payloads, and in a small number of cases hands-on-keyboard activity. Multiple reports describe a multi-stage infection chain that ultimately delivered an infostealer targeting browsers.
On Windows, the compromise used DLL sideloading while preserving normal application functionality. Reported components included 3CXDesktopApp.exe, a clean d3dcompiler_47.dll loader, and a maliciously patched ffmpeg.dll containing an appended encrypted payload and an embedded URL used to fetch encoded .ico payloads from GitHub raw content under https://raw.githubusercontent.com/IconStorages/images/main/. On macOS, the malicious component was a trojanized libffmpeg.dylib. Reported dropped artifacts on macOS included ~/.session-lock, ~/.main_storage, and an UpdateAgent path under ~/Library/Application Support/3CX Desktop App/. The malware also used a manifest/timestamp delay mechanism that could postpone follow-on activity for up to about 28 days.
Affected versions explicitly identified in the reporting were Windows Update 7 builds 18.12.407 and 18.12.416, and Electron Mac App builds 18.11.1213, 18.12.402, 18.12.407, and 18.12.416. Android and iOS were reported as not believed to be affected. The issue was tracked as CVE-2023-29059. Public reporting cited observations from CrowdStrike, SentinelOne, Sophos, CISA, Elastic, and Volexity. Sophos reported that the shellcode loader used in the campaign was a byte-for-byte match with tooling previously seen in incidents attributed to the Lazarus group, suggesting possible Lazarus involvement, though other reporting noted attribution was unclear at the time. The campaign reportedly began as early as February 2022, and the trojanized binaries were signed with a valid 3CX code-signing certificate before that certificate was later invalidated and replaced.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A trojanized version of the legitimate 3CX desktop application used in a supply chain attack. It beacons to attacker-controlled infrastructure and deploys follow-on payloads.
Trojanized, digitally-signed 3CX desktop client distributed via a supply-chain compromise. Uses DLL sideloading (Windows) / trojanized dylib (macOS) to execute embedded shellcode, delay execution via a timestamp/manifest mechanism, and retrieve additional payloads (including an infostealer) from attacker-controlled infrastructure (e.g., GitHub-hosted encoded payload).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.