HomeSecurityThe attack on the 3CX supply chain was caused by… another attack on...

3CX supply chain attack was caused by… another supply chain attack

In a detailed analysis of the cyberattack that infiltrated corporate phone provider 3CX, incident responders found that it was caused by another supply chain attack.

See also: Ransomware groups use AuKill to disable EDR software

3CX

3CX, whose software phone system is used by 600,000 organizations worldwide and has 12 million daily users, worked with security firm Mandiant to assess the incident. In a statement issued Thursday, Mandiant said the hackers had exploited 3CX using a financial program called X_Trader that had been infected with malware from Trading Technologies.

Despite being phased out in 2020, X_Trader was still available for download from Trading Technologies’ website two years later, according to Mandiant. This platform allowed traders to view both real-time and historical markets .

Mandiant believes the Trading Technologies website was compromised by a North Korean state-backed hacking group it calls UNC4736.

See also: Hackers actively exploit critical RCE bug in PaperCut servers

According to a 2021 report by Google’s threat analysis team, the Trading Technologies website was hacked in February 2022 as part of a North Korean mission to exploit dozens of cryptocurrency and fintech users. The cybersecurity agency CISA said the hacking group deployed the specialized “AppleJeus” malware to steal digital currency from 30 countries around the world.

As Mandiant revealed, a hacker managed to digitally forge the signature of 3CX’s code signing certificate in April 2022 and upload it to Trading Technologies’ website. As a result, a 3CX employee unknowingly downloaded this modified version of the X_Trader software, without receiving any indication that anything was amiss.

Once installed, the malware created a backdoor on the employee’s system, giving the attackers full access to it. This privilege was then used to browse the 3CX network and, ultimately, infiltrate their flagship desktop phone app in order to install data-stealing malware on their customers’ corporate networks

3CX supply chain attack was caused by… another supply chain attack

On April 11, Mandiant notified Trading Technologies of the potential breach. Unfortunately, there is still no definitive answer on how many users may have been affected.

See also: Microsoft SQL servers compromised for Trigona ransomware deployment

Ellen Resnick, a spokesperson for Trading Technologies, told TechCrunch that the company has yet to confirm Mandiant’s findings, and that they stopped offering support for the software in 2020.

With great certainty, Mandiant's Carmakel believes that many more targets of the two supply chain attacks will be exposed in the near future.

Information source: techcrunch.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS