Millions at Risk: 3CX Desktop App Compromised in Supply Chain Attack

1 min read
Source: The Hacker News
Millions at Risk: 3CX Desktop App Compromised in Supply Chain Attack
Photo: The Hacker News
TL;DR Summary

Cybersecurity vendors have warned of an active supply chain attack that is using digitally signed and rigged installers of the popular voice and video conferencing software, 3CX Desktop App, to target downstream customers. The attack, dubbed SmoothOperator, is the first stage in a multi-stage attack chain that pulls ICO files appended with Base64 data from GitHub and ultimately leads to a third-stage infostealer DLL. The attack may have commenced around March 22, 2023. 3CX is working on a software update for its desktop app and is urging its customers to uninstall the app and install it again or use the PWA client as a workaround. The attack has been attributed with high confidence to a North Korean nation-state actor, Labyrinth Chollima.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

3 min

vs 4 min read

Condensed

81%

640121 words

Want the full story? Read the original article

Read on The Hacker News