Federal Criminal Record investigation
3CX DesktopApp Cascading Supply Chain Attack (Lazarus Group)

North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.

Loss Amount $85M
Techniques 2 Mapped
Threat Actor Individual