Skip to main content

Active Intrusion Campaign Targeting 3CXDesktopApp Customers

  • March 30, 2023
  • 5 comments
  • 71 views

dips
Forum|alt.badge.img+7
  • On the path to Greatness

Something to watch out for if you are using the 3CXDesktopApp in your environment. There is not much info available at the moment but according to CrowdStrike:

“The malicious activity includes beaconing to actor-controlled infrastructure, deployment of second-stage payloads, and, in a small number of cases, hands-on-keyboard activity. “

More here: 

5 comments

Michael Melter
Forum|alt.badge.img+12

That’s quite an attack. We right away informed customers we know to use 3CX systems.

Here some recent intel from 3CX: https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/


marco_s
Forum|alt.badge.img+8
  • On the path to Greatness
  • March 30, 2023

It seems “only”  version numbers 18.12.407 & 18.12.416 are affected: https://www.3cx.com/blog/news/desktopapp-security-alert/


Iams3le
Forum|alt.badge.img+11
  • Veeam Legend
  • March 30, 2023

Great share @dips!


dips
Forum|alt.badge.img+7
  • Author
  • On the path to Greatness
  • March 30, 2023

It's going to be really interesting once the info is out about what exactly happened but looks to be quite bad. Especially with the large amount of high profile clients


Chris.Childerhose
Forum|alt.badge.img+21

Never really heard about this technology but interesting read for sure. Thanks for sharing.