/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers say hackers have compromised the 3CX VoIP IPBX desktop app, used by 600K+ companies and 12M+ daily users, in an ongoing supply chain attack

A digitally signed and trojanized version of the 3CX Voice Over Internet Protocol (VOIP) desktop client is reportedly being used to target …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This report extends a recurring supply-chain-security pattern in the coverage, including a 2021 demonstration that an open-source ecosystem flaw could provide a path into more than 35 companies. Here, the compromised distribution channel is a signed desktop communications client used across a broad customer base.

The incident matters beyond 3CX because a later investigation characterized the campaign as a confirmed case of one software-supply-chain attack enabling another, showing how a vendor compromise can become a launch point against its customers.

First-order effects

  • 3CX customers using the trojanized desktop client face an immediate endpoint-trust problem: a digitally signed application can no longer be treated as sufficient evidence that the delivered software is safe.
  • 3CX must contain the compromised distribution path and restore confidence in its client releases, while affected organizations must identify exposure among users of the desktop app.

Second-order effects

  • Security teams and software vendors face pressure to validate release pipelines and software provenance rather than relying primarily on code-signing status.
  • Because the compromised client sits in a communications environment, downstream customer targeting can turn a vendor-side breach into a wider enterprise incident, as the later customer-onward attack finding illustrates.

Third-order effects

  • If such campaigns persist, software supply-chain defense will shift toward stronger chain-of-custody controls for build, signing, and update systems—not just protection of end-user devices.
  • The strategic risk is increasingly concentrated in trusted software distributors: compromising one vendor can create access opportunities across its customer base, though the scale of any campaign still depends on detection and containment.

The trend: This is one data point in the shift from attacks on individual organizations toward attacks on the trusted software channels that connect vendors to many customers.

Discussion

  • 3CX Forums Nick Galea on x
    3CX DesktopApp Security Alert
  • @_johnhammond John Hammond on x
    3cx official post. https://www.3cx.com/...
  • @weldpond Chris Wysopal on x
    This supply chain attack, dubbed ‘SmoothOperator’ by SentinelOne, starts when the MSI installer is downloaded from 3CX's website or an update is pushed to an already installed desktop application. https://www.bleepingcomputer.com/ ...
  • @vxunderground @vxunderground on x
    @CrowdStrike ... .@SentinelOne has released an in-depth analysis of the malware and payload, they have dubbed it ‘SmoothOperator’. The final payload exfiltrates data from web browsers Chrome, Edge, Brave, and Firefox. tl;dr largest data theft in history? https://www.sentinelone.c…
  • @gi7w0rm @gi7w0rm on x
    ⚠️ @SentinelOne is investigating an ongoing supply chain attack on the #3CXDesktopApp. 3CXDesktopApp is a voice and video conferencing Private Automatic Branch Exchange (PABX) enterprise call routing software developed by 3CX, a business communications https://www.sentinelone.com…
  • @kostastsale Kostas on x
    There is a cred harvesting aspect, as noted by SentinelOne 👇 https://www.sentinelone.com/ ... This happens after the payload is downloaded from GitHub and runs in memory. DPRK is once again looking to fund their operations by emptying your people's bank account and bitcoin wallet…