A supply-chain compromise of the 3CX Desktop App caused legitimate, signed Windows and macOS clients to distribute malware, an incident tracked as CVE-2023-29059. Investigations by VMware, Rapid7, Fortinet, and Splunk found that affected Electron-based builds, including Windows versions 18.12.407 and 18.12.416 and several macOS releases, contained a maliciously altered bundled library. On Windows, the attack chain used a sideloaded ffmpeg.dll to decrypt or load code hidden in d3dcompiler_47.dll, then contact attacker-controlled infrastructure through GitHub-hosted .ico files that concealed command-and-control data.
Researchers reported that the malware collected host identifiers such as the MachineGUID, reached out to malicious domains and GitHub repositories for second-stage payloads, and ultimately delivered a browser-stealing DLL targeting data from Chrome, Firefox, Edge, and Brave. VMware telemetry observed related command-and-control traffic as early as early March, while Fortinet said victim connections were concentrated in Europe and North America. 3CX revoked the certificate for the prior Windows version, said malicious domains and the GitHub repository were taken down, and advised customers to uninstall the desktop client and temporarily use the browser-based Progressive Web App (PWA) while defenders hunt for indicators of compromise and block known-bad infrastructure.

Trace attribution and downstream blast radius.
14 events from the most recent confirmed update back to the earliest known activity.
On April 21, 2023, Symantec reported that a Trojanized Trading Technologies X_Trader installer was the upstream supply-chain compromise that led to the 3CX breach. The report also identified additional victims beyond 3CX customers, including two energy-sector critical infrastructure organizations in the U.S. and Europe and two financial trading firms.
Mandiant reported that the 3CX software supply-chain compromise was initiated through a prior software supply-chain compromise and assessed that a suspected North Korean threat actor was responsible. This added a new attribution element to the incident beyond earlier reporting on the compromise itself.
On March 30, 2023, OALABS published reverse-engineering details showing the signed 3CXDesktopApp MSI contained a trojanized ffmpeg.dll that decrypted and launched a stage 2 payload hidden inside a signed Microsoft d3dcompiler_47.dll. The analysis also described GitHub-hosted icon files used to deliver encoded C2 configuration and identified pbxsources[.]com/exchange as a decoded endpoint for the next-stage payload.
3CX confirmed the compromise on March 30, 2023, identifying affected Electron app versions for Windows and macOS. The incident was tracked as CVE-2023-29059 and involved maliciously altered bundled libraries in signed installers.
On the evening of March 29, 2023, Rapid7 contacted GitHub's security team about a repository being used as adversary infrastructure in the 3CX campaign. GitHub suspended the malicious user and removed the repository by 9:40 PM ET that night.
Security firms began warning about malicious activity involving the legitimate signed 3CXDesktopApp on March 29, 2023, with CrowdStrike announcing an active intrusion campaign targeting 3CX customers. Reports described the incident as a software supply-chain compromise affecting Windows and macOS environments.
VMware Contexa detected the first connections to akamaitechcloudservices[.]com on March 6, 2023, and additional connections to multiple malicious domains on March 7. These detections predated public reporting of the 3CX supply-chain compromise.
Volexity reported that infrastructure used by the Windows variant of the 3CX malware was active by December 7, 2022, based on recovered GitHub data. The first GitHub commit containing an ICO file with encrypted 3cx[.]com URL data suggested the attackers were testing delivery infrastructure by that date.
A Censys search indicated the host for visualstudiofactory[.]com had been online since November 19, 2022. VMware later cited this as part of the command-and-control infrastructure associated with the 3CX compromise.
CVE-2023-29059 was assigned to the 3CXDesktopApp supply-chain compromise on April 3, 2023. The CVE tracked the trojanized signed desktop application affecting Windows and macOS builds.
3CX released new versions of its Windows and Mac Electron applications on March 31, 2023. The company said the update was considered secure, while cautioning that only 24 hours had been available to make adjustments.
FortiGuard Labs reported observing connections to known malicious domains associated with the attack as of March 31, 2023. Its telemetry showed most observed victim connections were concentrated in Europe and North America.
3CX and multiple defenders advised customers to uninstall the 3CX desktop application and hunt for indicators of compromise. 3CX also said malicious domains and the GitHub repository used in the attack had been taken down, while Mandiant was engaged for forensic assistance.
During the response to the compromise, 3CX revoked the certificate for the prior Windows version and advised users to migrate temporarily to the unaffected Progressive Web App. It also said it was working on a new Windows version while clean replacements were not yet fully available.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 145 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
14 references tracked. Mallory keeps watching after this page renders.
group-ib.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcemandiant.com
Open sourceblogs.vmware.com
Open source3cx.com
Open sourcecve.mitre.org
Open source3cx.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.