Skip to content

Instantly share code, notes, and snippets.

@SwitHak
Last active April 6, 2023 09:26
Show Gist options
  • Save SwitHak/dccc91ef8a958bb5a4ee4d279a870e02 to your computer and use it in GitHub Desktop.
Save SwitHak/dccc91ef8a958bb5a4ee4d279a870e02 to your computer and use it in GitHub Desktop.
BlueTeam CheatSheet *3CX-Event-March2023* | Last updated: 2023-04-06 0926 UTC

Security Advisories / Bulletins / vendors Responses linked to 3CX compromise event

General

What's 3CX?

  • 3CX evolved from its roots as a PBX phone system to a complete communications platform, offering customers a simple, flexible, and affordable solution to call, video and live chat.

What's happening?

  • Per several report the building environment of 3CX for the DesktopApp (MAC & Windows) has been compromised
  • The recent releases (details given below) have been compromised to include malicious code inside it
  • More details available regarding the compromise with the graphics by Thomas Roccia:
  • 3CX Supplychain Attack Windows
  • 3CX Supplychain Attack Apple

Reach of the compromise

  • Per 3CX website, likely numbers not updated:
  • 190 Countries
  • 600K+ installations
  • 12M+ users

Affected ?

Affected Releases

  • The following releases & platforms are affected
  • Microsoft / Electron Windows App shipped in Update 7, version numbers 18.12.407 & 18.12.416.
  • Mac / Electron Mac App version numbers 18.11.1213, 18.12.402, 18.12.407 & 18.12.416 are also affected.

CVE Number

Vendor response

Vendor Forum Threads about AV detecting 3CX

NOTA

  • Thanks to Crowdstrike for the burn of this with their Reddit post they did the right thing.

CyberSecurity vendors blogs

Crowdstrike

SentinelLabs

Sophos

Huntress

Elastic ecurity Labs

Reversing Labs

PAN

Trend Micro Research

Volexity

Checkpoint Research

Objective See

Fortinet

Orange Cyberdefense

Symantec (Broadcom)

Cyble

Nextron Systems

Automox

Malwarebytes

Rapid7

Talos (Cisco)

Trustwave

Blackberry

VMware

Threat Radar

Kaspersky

Todyl

Splunk

Zscaler

Microsoft

Errors, typos, something to say ?

  • If you want to add a link, comment or send it to me
  • Feel free to report any mistake directly below in the comment or in DM on Twitter @SwitHak
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment