A supply-chain compromise of 3CXDesktopApp distributed digitally signed, trojanized installers to customers and triggered widespread detections in March 2023. Researchers said the operation, tracked as SmoothOperator, likely involved attacker infrastructure prepared as early as February 2022, while later reporting tied the campaign to the North Korea-linked Lazarus Group with medium to high confidence based on overlaps with AppleJeus infrastructure and malware traits.
Investigators found the 3CX intrusion was itself enabled by an earlier software supply-chain breach, extending the attack chain beyond a single vendor compromise. Although the malicious 3CX software reached organizations globally, a more selective second stage delivered the Gopuram backdoor to fewer than ten machines, with cryptocurrency companies identified among the high-value targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Mandiant reported that the 3CX compromise itself was the result of a previous software supply-chain intrusion, adding a new upstream stage to the incident timeline.
Kaspersky said with medium to high confidence that the 3CX supply-chain attack was connected to North Korea-linked Lazarus, citing overlaps with AppleJeus infrastructure and malware traits.
Kaspersky reported that the campaign delivered the Gopuram backdoor to fewer than ten machines, including cryptocurrency companies, showing that only a small subset of victims received the second-stage payload.
Digitally signed 3CXDesktopApp installers were compromised and delivered to 3CX customers as part of a supply-chain attack. The malicious software later enabled follow-on targeting of selected victims.
Security vendors began seeing broad detections tied to the malicious 3CX software around March 22, 2023, bringing the supply-chain attack to light.
Researchers assessed that infrastructure used in the 3CX supply-chain operation may have been set up as early as February 2022, indicating long-term preparation before the malware was distributed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.