A supply-chain compromise of 3CXDesktopApp delivered the SmoothOperator malware to Windows and macOS users, turning a widely used enterprise PBX and conferencing client into a staged malware loader. SentinelLabs reported that trojanized Windows installers triggered detections after a spike in malicious activity, with the application loading shellcode, reflectively loading DLLs, retrieving poisoned .ico files from GitHub containing appended Base64 data, decrypting a command-and-control URL, and ultimately deploying a third-stage infostealer that harvested host information and browser history. On macOS, investigators found a malicious libffmpeg.dylib embedded in the installer; it was code-signed and notarized at discovery, then later revoked by Apple.
Technical analysis of the Windows payload chain showed a two-DLL staging process in which an initial DLL acted as a PE loader for d3dcompiler_47.dll, searched for a marker in its Security directory, unpacked shellcode, and mapped an in-memory 64-bit DLL before transferring execution to DllGetClassObject. Researchers noted API hashing consistent with Metasploit-style routines, a hard-coded 3CXDesktopApp user-agent string, and possible anti-emulation logic using cpuid. On macOS, the first stage collected environment data, contacted a hardcoded C2, and dropped UpdateAgent, which gathered 3CX account and provisioning details before self-deleting. Mandiant later said the backdoor on 3CX’s macOS build server was POOLRAT, not SIMPLESEA, linking the intrusion to malware previously associated with Lazarus activity, though attribution remained cautious at the time.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
On March 29, 2023, cybersecurity vendors announced a supply-chain attack affecting 3CXDesktopApp users. Initial reporting attributed the intrusion campaign to the North Korean-linked threat actor Labyrinth Chollima.
SentinelOne observed a spike in behavioral detections involving 3CXDesktopApp beginning March 22, 2023. Its protections blocked execution of trojanized installers and quarantined them by default.
SentinelLabs reported that infrastructure used in the 3CX SmoothOperator campaign had registration dates going back to at least February 2022.
On April 24, 2023, SentinelLabs added additional technical details covering both the Windows and macOS variants of the 3CX malware.
A malware-analysis write-up documented the SmoothOperator two-DLL staging process, including a first-stage PE loader, shellcode that maps a DLL in memory, Metasploit-style API hashing, and execution via DllGetClassObject.
SentinelLabs updated indicators of compromise for the 3CX campaign on March 30, 2023 with contributions from the research community.
Apple revoked the code signature and notarization for the trojanized macOS 3CX application on March 30, 2023 after public reporting.
On March 30, 2023, SentinelLabs confirmed that the macOS 3CX installer was also trojanized, matching earlier triage by Patrick Wardle. The malicious package used a crafted libffmpeg.dylib inside the app bundle.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcegithub.com
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.