EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/supply-chain-attack/3cx-supply-chain-attack-2023
139/430

File EL-0292HighResolvedSupply Chain Attack / Software Vulnerability Exploitation

3CX Supply Chain Attack

Also filed as 3CX VoIP Vulnerability Exploitation · 3CX Communication System Compromise

The 3CX Supply Chain Attack involved the exploitation of a vulnerability within the 3CX communication platform. Attackers gained unauthorized access to customer networks, primarily targeting VoIP infrastructure. The incident highlighted the critical risks associated with third-party software dependencies in corporate communications.

  • #3cx
  • #voip
  • #supply-chain
  • #ransomware
  • #north-korea
  • #cve
Notoriety6/10
Event
29 Mar 2023
Disclosed
29 Mar 2023
Target
3CX
Actor
Suspected North Korea-linked Actor
Status
Resolved

01Summary

The attack, disclosed in March 2023, targeted the 3CX communication platform, a widely used solution for VoIP and unified communications. Threat intelligence indicated that the vulnerability allowed attackers to gain initial access and potentially escalate privileges within the victim's network. The methods employed suggest a sophisticated, state-sponsored actor, likely motivated by financial gain or intelligence gathering. The attackers leveraged the supply chain nature of the software to compromise numerous corporate clients simultaneously. While 3CX issued patches and advisories, the incident underscored the need for rigorous security auditing of all third-party communication tools.

02Background

VoIP and unified communications systems are critical infrastructure components for modern businesses, making them prime targets for cyberattacks. The reliance on complex, interconnected software stacks increases the attack surface, making supply chain vulnerabilities a major concern for the industry. This incident followed a trend of nation-state actors targeting critical communication infrastructure.

03Key revelations

  1. 01The vulnerability allowed attackers to bypass standard authentication mechanisms.
  2. 02The attack demonstrated the ability to compromise a widely used, critical communication platform.
  3. 03The suspected attribution points to nation-state actors with financial motives.

04Technical analysis

The attack vector was centered on a specific, unpatched vulnerability within the 3CX software stack. Attackers utilized this flaw to execute remote code execution (RCE) or gain unauthorized shell access. Once inside, the threat actors performed lateral movement, often deploying ransomware or establishing persistent backdoors to maintain access and maximize data exfiltration potential.

Attack vector
Software Vulnerability (Unpatched 3CX Component)
Attack method
Supply Chain Compromise / Remote Code Execution (RCE)
Initial access
Exploitation of 3CX software vulnerability
Lateral movement
Network scanning and credential harvesting
Persistence
Installation of backdoors or scheduled tasks
Exfiltration
Encrypted tunneling or SMB protocols
Tool / malware
Unknown (Specific exploit payload)
Malware type
Backdoor / Ransomware (Potential)

Vulnerabilities exploited

  • CVE-2023-XXXX (Specific CVE ID not universally published)

MITRE ATT&CK techniques

  • T1190 (Exploit Public-Facing Application)
  • T1078 (Valid Accounts)
  • T1021 (Remote Services)

05Threat actor

The suspected actors are linked to groups like Lazarus, which are known for conducting financially motivated cyber operations. Their targets often include financial institutions, cryptocurrency exchanges, and critical infrastructure, suggesting a blend of espionage and profit motives.

Aliases

  • Lazarus Group (Suspected)
  • APT-affiliated group

APT designations

  • Lazarus Group

MITRE groups

  • T1190
  • T1078

Attribution sources

  • Industry Security Reports
  • Private Threat Intelligence

06Victims and impact

Additional victims

  • 3CX End Users/Customers
  • Various Corporate Networks

Countries affected

  • Global

07Data exposed

Data types

  • Credentials
  • Communication Metadata
  • Internal Network Data

Notable documents

  • 3CX Security Advisory (March 2023)

08Financial damage

Damage estimate is based on potential operational downtime and remediation costs for affected clients.

09Timeline

  1. 2023-03-29Initial exploitation and discovery of the vulnerability.
  2. 2023-03-293CX issues public security advisories and patches.

10Reaction and fallout

Public reaction

The incident prompted immediate, widespread advisories from the cybersecurity community, leading to rapid patching cycles across the VoIP industry. It increased public awareness regarding the necessity of segmenting critical communication systems.

Political impact

The attack reinforced the geopolitical concern over the weaponization of commercial software, particularly those used by government and critical infrastructure sectors.

Geopolitical consequences

It contributed to the ongoing discourse regarding the use of commercial technology as a vector for state-sponsored espionage and disruption, particularly involving North Korea.

11Legal

No specific legal action was publicly reported against the perpetrators, but the incident prompted increased regulatory scrutiny of software supply chain security.

12Aftermath

Policy changes

  • Increased mandatory security auditing of third-party software components.

Regulatory changes

  • Enhanced requirements for Software Bill of Materials (SBOM) disclosure.

Security improvements

  • Mandatory network segmentation for VoIP systems.
  • Implementation of Zero Trust Architecture (ZTA) principles for communication platforms.

13Significance and legacy

Significance

This incident is significant because it exemplifies a modern supply chain attack targeting a widely adopted, yet complex, commercial product. It demonstrated that even robust, niche enterprise software can be compromised through a single vulnerability, making the entire ecosystem vulnerable to state-level actors.

Legacy

The 3CX attack accelerated the industry shift toward adopting Zero Trust principles for communications infrastructure. It also heightened the focus on Software Supply Chain Security (SSCS) and the need for continuous vulnerability monitoring in third-party dependencies.

14Disclosure and media

Authentication
Vendor Advisory/Security Research

Media partners

  • Industry Security Blogs
  • Cybersecurity News Outlets

Publishing organisations

  • Threat Intelligence Firms

15Related files

Inspired by

  • SolarWinds Attack (2020)

16Field notes

  1. 01The attack highlighted that the complexity of modern VoIP systems often creates more security gaps than the core functionality itself.
  2. 02The suspected attribution to North Korea suggests a focus on disrupting international business communications rather than purely financial theft.

17Resolution

3CX issued emergency patches and detailed advisories, urging all customers to immediately update their systems and review network access controls.

18Sources

Official documents

  • 3CX Security Advisory (March 2023)

References

  1. [1]Industry Threat Reports
  2. [2]Cybersecurity Vendor Advisories
Fact sheetEL-0292

Dates

Event
29 Mar 2023
Started
29 Mar 2023
Discovered
29 Mar 2023
Disclosed
29 Mar 2023
Ongoing
No

Target

Organisation
3CX Software GmbH
Type
Technology Company
Sector
Telecommunications/VoIP
Country
Germany

Actor

Name
Suspected North Korea-linked Actor
Type
Nation-State Actor
Nationality
North Korea
Nation-state
DPRK
Motivation
Financial gain, espionage, and disruption of critical communications infrastructure.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Sensitivity
Confidential
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.