Several cybersecurity firms have issued warnings that the VoIP solution offered by 3CX, which is used by some of the biggest brands in the world, is under threat by cyber attackers. Sophos and CrowdStrike have identified that compromised 3CX desktop clients on both Windows and macOS are being actively targeted by threat actors. According to BleepingComputer, 3CX’s VoIP platform has more than 600,000 customers and over 12 million daily users, with clients such as Coca-Cola, BMW, McDonald’s, and American Express.
The 3CXDesktop App versions 18.12.407 and 18.12.416 for Windows, and 18.11.1213 for macOS, are vulnerable. One of the trojanized clients was digitally signed by DigiCert using a legitimate 3CX certificate in early March, which could potentially allow hackers to steal sensitive data. Cybersecurity firms have reported that the malware is capable of stealing system information and data stored in Chrome, Edge, Brave, and Firefox browsers, including login credentials and payment information.
CrowdStrike suspects that North Korean state-sponsored hacking group Labyrinth Chollima is behind the attacks, which include beaconing to actor-controlled infrastructure, deployment of second-stage payloads, and hands-on-keyboard activity in some cases. Sophos also warned of the spawning of an interactive command shell as the most common post-exploitation activity observed so far.
3CX has acknowledged the attack on its blog and confirmed that it is working on a fix, apologizing for any inconvenience and assuring its partners and customers that it is doing everything in its power to make up for the error.
As a provider of VoIP solutions, it is crucial to prioritize cybersecurity and ensure that your business is not susceptible to attacks. Stay vigilant and work with a reputable cybersecurity firm to protect your business and your clients’ sensitive data.

No responses yet