Logo
News

Supply chain attack targets millions of phone system users through trojanized 3CX app

Cybersecurity firms have been warned of a supply chain attack targeting downstream customers using a trojanized 3CX software

Supply chain attack targets millions of phone system

Multiple cybersecurity firms have warned of a supply chain attack using a trojanized version of 3CX's software to target downstream customers. 

3CX is a phone system developer used by more than 600,000 organizations worldwide, including American Express, BMW, McDonald’s, and the U.K.'s National Health Service. The attack, dubbed "Smooth Operator," involves the delivery of trojanized 3CXDesktopApp installers to install infostealer malware inside corporate networks, capable of stealing data and stored credentials from Google Chrome, Microsoft Edge, Brave, and Firefox user profiles. 

Researchers report that attackers are targeting both the Windows and macOS versions of the compromised VoIP app. The Linux, iOS, and Android versions appear to be unaffected. The attackers are believed to be the North Korean threat actor Labyrinth Chollima, a subgroup of the notorious Lazarus Group. It appears to be a targeted attack from an Advanced Persistent Threat, perhaps even state-sponsored. 

If you are a 3CX user, the company suggests uninstalling the app and installing it again or using its PWA client as a workaround. While we don't know how many organizations have been potentially compromised, Shodan.io reports that there are currently over 240,000 publicly exposed 3CX phone management systems. 

Stay vigilant and take immediate action if you suspect any suspicious activity.

Manish
Written By
Manish

With a mixture of literature, cinema, and photography, Manish is mostly traveling. When he is not, he is probably writing another tech news for you!

Think Your Professional Journey
Deserves A Spot In Our 40 Under 40 Report?

Featured Blogs

News

Apple Music Expanding Student Subscription Plan

4 min read  

Apple Music has remained successful in making similar price strategy and succeeding them as well in the past in countries like UK, US, Germany, Australia, Denmark, Ireland, and New Zealand since 2016. With the latest initiative, the giant is expanding its market by making Apple Music available to al

News

Twitter Camera Feature Is Rolling Out And You Should Be Happy

2 min read  

Here is good news for all the Twitteraties. In a bid to demote texting on the social media platform, Twitter has launched a camera feature that lets the user capture photos, videos and goes live which can connect them to global conversations.To access the new Twitter camera feature, the user has

News

Paranoid Android Got New Update With 7.2 Version Which Comes With New Features

4 min read  

Firstly, for the ones who are not aware of the Paranoid Android, it is an open source operating system for smartphones and tablet computers, based on the Android mobile platform. Paranoid Android surprised everyone with the stupendous features and upgrades a month ago with the release of the new ver

News

AI Powered Music Startup Musiio Raises $1M

4 min read  

Musiio, a Singapore-based AI music startup that helps digital music companies with discovery and creation through Artificial Intelligence has raised $1 million in seed funding.The investment round was led by Wavemaker Partners, U.S. investor Exponential Creativity Ventures, and other angel inves

Featured Interviews

Interview

Interview With Coyote Jackson, Director of Product Management, PubNub

MobileAppDaily had a word with Coyote Jackson, Director of Product Management, PubNub. We spoke to him about his journey in the global Data Stream Network and real-time infrastructure-as-a-service company. Learn more about him.

MAD Team 4 min read  
Interview

Interview With Laetitia Gazel Anthoine, Founder and CEO, Connecthings

MobileAppDaily had a word with Laetitia Gazel Anthoine, Founder and CEO, Connecthings. We spoke to her about her idea behind Connecthings and thoughts about the company’s services.

MAD Team 4 min read  
Interview

Interview With Gregg Temperley, Founder Of ParcelBroker App

MobileAppDaily had a word with Gregg Temperley, Founder. We spoke to him about his idea behind such an excellent app and his whole journey during the development process.

MAD Team 4 min read  
Interview

Interview With George Deglin, CEO Of OneSignal

MobileAppDaily had a word with George Deglin, the CEO and co-founder of OneSignal, a leading customer messaging and engagement solution, we learn multiple facets related to customer engagement, personalization, and the future of mobile marketing.

MAD Team 4 min read  
MAD Originals
MAD Originals

Cut to the chase content that’s credible, insightful & actionable.

Get the latest mashup of the App Industry Exclusively Inboxed

  • PRODUCTS
  • SERVICES
  • BOTH
Join our expansive network, build connections and expand your brand presence.