{
  "id": "case-3cx-supply-chain",
  "slug": "3cx-desktop-app-supply-chain",
  "title": "3CX DesktopApp Cascading Supply Chain Attack (Lazarus Group)",
  "summary": "North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.",
  "case_number": "Mandiant-3CX-Investigation-2023",
  "court": "National Cyber Security Centre & Mandiant Forensic Reports",
  "district": "Global / Federal Republic of Germany",
  "country": "International / United States",
  "opened_at": "2023-03-29",
  "status": "investigation",
  "victim_sector": "Telecommunications & Enterprise VoIP",
  "victim_country": "Global",
  "loss_amount_usd": 85000000,
  "loss_amount_note": "Global enterprise security containment, code signing certificate revocations, and application rebuilds.",
  "first_seen_at": "2023-03-01T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "lazarus-group",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1195.002",
      "evidence_excerpt": "Malicious code was compiled into ffmpeg.dll and d3dcompiler_47.dll, which were digitally signed by 3CX legitimate Apple and Windows certificates.",
      "evidence_locator": "Mandiant Technical Report: 3CX Software Supply Chain Compromise",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Mandiant Forensic Investigation Report on 3CX",
      "source_url": "https://cloud.google.com/blog/topics/threat-intelligence"
    },
    {
      "technique_id": "T1071.001",
      "evidence_excerpt": "The backdoored desktop client pulled encrypted icon files containing base64 command-and-control server domains from public GitHub repositories.",
      "evidence_locator": "CISA Alert AA23-090A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert on 3CX Compromise",
      "source_url": "https://www.cisa.gov",
      "technique_name": "Web Protocols",
      "tactic": "Command and Control"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2023-03-08",
      "description": "3CX signs and distributes trojanized desktop application update to global customers."
    },
    {
      "event_type": "discovery",
      "event_date": "2023-03-29",
      "description": "CrowdStrike and SentinelOne publicly flag 3CXDesktopApp as malicious."
    },
    {
      "event_type": "disclosure",
      "event_date": "2023-04-20",
      "description": "Mandiant reveals initial compromise stemmed from employee downloading infected Trading Technologies software."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Telecommunications & Enterprise VoIP networks. North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.",
    "blast_radius": "Global enterprise security containment, code signing certificate revocations, and application rebuilds. Impacted Telecommunications & Enterprise VoIP infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the Telecommunications & Enterprise VoIP sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}