Skip to main content

Active Intrusion Campaign Targeting 3CXDesktopApp Customers


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments

Something to watch out for if you are using the 3CXDesktopApp in your environment. There is not much info available at the moment but according to CrowdStrike:

“The malicious activity includes beaconing to actor-controlled infrastructure, deployment of second-stage payloads, and, in a small number of cases, hands-on-keyboard activity. “

More here: 

5 comments

Michael Melter
Forum|alt.badge.img+12

That’s quite an attack. We right away informed customers we know to use 3CX systems.

Here some recent intel from 3CX: https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/


marco_s
Forum|alt.badge.img+8
  • Influencer
  • 369 comments
  • March 30, 2023

It seems “only”  version numbers 18.12.407 & 18.12.416 are affected: https://www.3cx.com/blog/news/desktopapp-security-alert/


Iams3le
Forum|alt.badge.img+11
  • Veeam Legend
  • 1389 comments
  • March 30, 2023

Great share @dips!


dips
Forum|alt.badge.img+7
  • Author
  • Veeam Legend
  • 808 comments
  • March 30, 2023

It's going to be really interesting once the info is out about what exactly happened but looks to be quite bad. Especially with the large amount of high profile clients


Chris.Childerhose
Forum|alt.badge.img+21

Never really heard about this technology but interesting read for sure. Thanks for sharing.


Comment