high_confidence

3CX Supply Chain Attack

The [3CX Supply Chain Attack](https://attack.mitre.org/campaigns/C0057) was the first publicly reported case of one supply chain compromise triggering another, leading to a cascading, two-stage intrusion. The initial supply chain attack began when a 3CX employee downloaded and executed a trojanized, end-of-life version of the X_Trader trading software from Trading Technologies. This provided UNC4736, a threat cluster associated with [AppleJeus](https://attack.mitre.org/groups/G1049), access to the 3CX environment. From there UNC4736 compromised the Windows and macOS build environments used to distribute the 3CX desktop application to their customers.(Citation: Mandiant 3cx UNC4736 2023) While 3CX serves more than 600,000 customers and 12 million users, only a subset of systems were affected. Subsequent targeting focused on victims in the defense and cryptocurrency sectors, where attackers deployed secondary payloads such as Gopuram for credential theft and persistence.(Citation: Kaspersky 3CX Gopuram 2023) The campaign began in late 2022 and was disrupted after security vendors publicly reported the compromise in March 2023.(Citation: 3cx official statement 2023)(Citation: Krebs 3cx overview 2023)

Start date
1 November 2022
End date
1 March 2023
Techniques
22

Attributed actors

Techniques (22)

command-and-control3
T1102.001Dead Drop Resolver
T1573.001Symmetric Cryptography
T1071.001Web Protocols
defense-impairment1
T1553.002Code Signing
discovery1
T1217Browser Information Discovery
execution3
T1203Exploitation for Client Execution
T1574.001DLL
T1559Inter-Process Communication
initial-access3
T1078Valid Accounts
T1189Drive-by Compromise
T1195.002Compromise Software Supply Chain
persistence3
T1078Valid Accounts
T1543.004Launch Daemon
T1546.016Installer Packages
privilege-escalation5
T1078Valid Accounts
T1543.004Launch Daemon
T1546.016Installer Packages
T1055Process Injection
T1055.002Portable Executable Injection
stealth11
T1027.009Embedded Payloads
T1078Valid Accounts
T1620Reflective Code Loading
T1678Delay Execution
T1574.001DLL
T1055Process Injection
T1055.002Portable Executable Injection
T1027Obfuscated Files or Information
T1218.007Msiexec
T1027.013Encrypted/Encoded File
T1218.015Electron Applications

Indicators of compromise

No IOCs linked to this campaign yet.