Massive supply chain attack targets 3CX users with Trojanized apps.

1 min read
Source: Ars Technica
Massive supply chain attack targets 3CX users with Trojanized apps.
Photo: Ars Technica
TL;DR Summary

North Korean hackers have carried out a massive supply chain attack on Windows and macOS users of 3CX, a widely used voice and video calling desktop client, compromising the software build system used to create and distribute Windows and macOS versions of the app. The attackers were able to hide malware inside 3CX apps that were digitally signed using the company’s official signing key. The attack is reminiscent of the SolarWinds supply chain attack detected in December 2020. Any organization that uses 3CX should immediately begin analyzing its network infrastructure to look for signs of compromise.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

4 min

vs 5 min read

Condensed

89%

89496 words

Want the full story? Read the original article

Read on Ars Technica