Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes. In March 2023, attackers compromised the software supply chain for the 3CX DesktopApp and distributed trojanized Windows and macOS releases through the company’s legitimate update channels. The affected applications were digitally signed and could arrive as routine updates. That did not mean every 3CX customer—or every 3CX product—was compromised: the confirmed affected software was specific DesktopApp versions, and installation alone does not prove that malware executed or that an attacker gained access.

What happened

The 2023 3CX incident was a software supply-chain compromise, not simply a case of attackers sending customers a fake update. Malicious code was included in particular versions of the legitimate 3CX DesktopApp, an Electron-based voice and video communications client. Those releases were signed with a legitimate 3CX code-signing certificate and distributed through ordinary 3CX software-delivery and update processes. A customer could therefore receive the compromised code while carrying out what appeared to be a normal software update.

The distinction matters. The evidence concerns specific Windows and macOS desktop clients; it does not establish that every 3CX PBX/server, browser-based Web App, mobile app, or customer environment was affected. CISA described the event as a supply-chain attack involving a trojanized application that could enable multistage attacks. See CISA’s 3CXDesktopApp alert and 3CX’s incident updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which 3CX versions were affected?

The historical affected-version information applies to the 3CX DesktopApp, not to every 3CX component. 3CX identified these releases:

#1 Best Overall
Sale
Webroot Antivirus Software 2026 | 3 Device | 1 Year Download for PC/Mac
  • POWERFUL, LIGHTNING-FAST ANTIVIRUS: Protects your computer from viruses and malware through the cloud; Webroot scans faster, uses fewer system resources and safeguards your devices in real-time by identifying and blocking new threats
  • IDENTITY THEFT PROTECTION: Protects your usernames, account numbers and other personal information against keyloggers, spyware and other online threats targeting valuable personal data
  • REAL-TIME ANTI-PHISHING: Proactively scans websites, emails and other communications and warns you of potential danger before you click to effectively stop malicious attempts to steal your personal information
  • ALWAYS UP TO DATE: Webroot scours 95% of the Internet three times per day including billions of web pages, files and apps to determine what is safe online and enhances the software automatically without time-consuming updates
Operating system Affected DesktopApp versions Release context
Windows 18.12.407 and 18.12.416 Update 7
macOS 18.11.1213, 18.12.402, 18.12.407 and 18.12.416 Electron DesktopApp releases

The NVD entry for CVE-2023-29059 describes malicious code in 3CX DesktopApp versions through 18.12.416 and records the affected Windows and macOS releases. The CVE helps identify the software condition; it does not prove that a particular endpoint ran the code or suffered a follow-on intrusion. These are historical 2023 versions, not current installation guidance. For a present-day environment, check your inventory and the latest 3CX and security-vendor advisories rather than relying on this old list alone.

How the attack chain worked

  1. An earlier supply-chain compromise preceded the 3CX breach. Mandiant’s investigation connected initial access to an employee’s personal computer that contained a malware-laced X_TRADER installer. That installer had been distributed through Trading Technologies’ website in an earlier incident.
  2. The attacker moved into the 3CX environment. The compromise of 3CX was therefore part of a nested supply-chain chain, rather than evidence that the attacker simply exploited a vulnerability in every customer’s PBX.
  3. Malicious code entered the DesktopApp delivery process. Particular application releases were packaged and signed as legitimate 3CX software.
  4. Customers received the trojanized client through normal distribution. The update channel and valid signature made the file look trustworthy; ordinary user caution or phishing training would not necessarily have stopped a routine vendor update.
  5. The client could launch additional stages. Mandiant reported a downloader called SUDDENICON. It retrieved further command-and-control information from encrypted icon files hosted on GitHub, enabling later payload delivery and activity.

For the X_TRADER connection and technical details, see Mandiant’s analysis of the 3CX supply-chain compromise and 3CX’s summary of Mandiant’s findings.

Rank #2
Sale
McAfee Total Protection | 3 Device | Antivirus Internet Security Software | VPN, Password Manager, Dark Web Monitoring | 1 Year Subscription | Download Code
  • MCAFEE TOTAL PROTECTION IS ALL-IN-ONE PROTECTION — delivering award-winning antivirus for 3 devices, with identity monitoring and VPN
  • ID MONITORING — we'll monitor everything from email addresses to IDs and phone numbers for signs of breaches. If your info is found, we'll notify you so you can take action
  • BANK, SHOP, AND BROWSE ANYWHERE SECURELY WITH UNLIMITED VPN — protect your online privacy automatically when connecting to public Wi-Fi
  • SECURE YOUR ACCOUNTS — generate and store complex passwords with a password manager
  • AWARD-WINNING ANTIVIRUS — rest easy knowing McAfee will notify you of risky websites and protect you from the latest threats

What the malware did—and what that does not prove

Researchers described malicious components, DLL side-loading behavior, a first-stage downloader, and infrastructure used to retrieve further instructions or payloads. SentinelOne covered the campaign under the name SmoothOperator; Mandiant reported SUDDENICON and connected relevant activity to POOLRAT. Some reporting also described attempts to access browser-related data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those technical findings should not be inflated into a claim that every affected installation stole passwords, cookies, cryptocurrency, or corporate files. The malware created a route to follow-on activity, but what happened depended on the operating system, the payload delivered, endpoint defenses, and whether the attackers continued beyond the first stage. A valid code signature does not settle the question of safety: it can confirm that a file was signed with a trusted certificate, but a compromised vendor build can still be malicious.

Rank #3
Sale
K7 Total Security Antivirus Software 2026 for laptop/pc |1 User, 1 year |Antivirus,Internet security,Data security,Threat Protection| 2hr Email Delivery-No CD
  • [Intelligent Antivirus] - Safeguards your laptop/pc against Viruses, Malware, Spyware, Phishing and other online threats.
  • [Ransomware Protection] - Photos and files in your windows laptop/pc are protected from ransomwares and other untrusted apps from changing, deleting or encrypting.
  • [Webcam Protection] - Prevents unauthorized applications and hackers from spying on you by blocking access to your webcam
  • [Internet Security] - Work, surf, bank and shop in complete confidence. K7 Total Security Antivirus software protects your online identity and Maintains Privacy.
  • [EMAIL DELIVERY] - After Purchase, the Activation Code & download link will be sent through 'Buyer/Seller messages' under Message Center and Activation Code will be mailed to your Amazon regd. email ID within 24 hrs.

Exposure is not the same as compromise

When investigating, keep four states separate:

  1. An affected release was available from the vendor.
  2. The release was downloaded or installed on an endpoint.
  3. The malicious component executed.
  4. The endpoint communicated with attacker infrastructure or experienced follow-on activity.

Evidence for one state does not automatically establish the next. A quarantined installer that never ran presents a different risk from a client that executed and then made suspicious outbound connections. Conversely, uninstalling the application does not undo credential theft, persistence, lateral movement, or activity that occurred before removal. 3CX advised customers to continue antivirus scans and use EDR capabilities during its response; see its security incident updates.

Who did researchers attribute the activity to?

Mandiant attributed the activity to a cluster it tracks as UNC4736 and assessed that the cluster was likely aligned with North Korea. CrowdStrike separately associated the campaign with LABYRINTH CHOLLIMA, its name for a North Korea-linked actor. These are threat-intelligence assessments, not court-established findings. Attribution is useful context, but an organization’s response should be based on endpoint and account evidence, not on attribution alone.

Rank #4
Webroot Internet Security Complete | Antivirus Software 2026 | 5 Device | 1 Year Keycard for PC/Mac/Chromebook/Android/IOS + Password Manager, Performance Optimizer and Cloud Backup | Packaged Version
  • NEVER WORRY about losing important files and photos again! With 25GB of secure online storage, you know your files are safe and sound.
  • KEEP YOUR COMPUTER RUNNING FAST with our system optimizer. By removing unnecessary files, it works like a PC tune-up, so you can keep working smoothly.
  • Our PASSWORD MANAGER by Last Pass creates, encrypts, and saves all your passwords, so you only have to remember one.
  • As the #1 TRUSTED PROVIDER OF THREAT INTELLIGENCE, Webroot protection is quick and easy to download, install, and run, so you don’t have to wait around to be fully protected.
  • STAY PROTECTED EVERYWHERE you go, at home, in a café, at the airport—everywhere—on ALL YOUR DEVICES with cloud-based protection against viruses and other online threats.

How to investigate a potentially affected environment

  1. Build an endpoint inventory. Search software-management records, endpoint management, EDR, and application logs for the 3CX DesktopApp on both Windows and macOS. Include laptops, remote devices, and personally owned devices used to access business accounts. Track servers separately: the desktop-client findings do not make a server-only deployment automatically affected.
  2. Establish presence and execution. Determine which affected versions were installed, when they were present, whether the application or installer launched, and whether security software blocked or quarantined it. Use endpoint timelines and process records where available.
  3. Review network and host telemetry. Examine process trees, DNS, proxy, firewall, and outbound HTTPS records. Search for indicators published by authoritative responders, but do not depend on an old hash list alone. Historical indicators can be incomplete, and a hash match cannot capture every renamed, repackaged, or later-stage artifact.
  4. Look for follow-on activity. Review for unusual accounts or privilege changes, scheduled tasks, persistence, remote-access tools, lateral movement, and unexpected browser-session use. Extend the timeline earlier than the first alert where possible.
  5. Assess identity exposure. If an endpoint executed the malicious client, consider credentials used from that system—especially privileged, VPN, cloud, password-manager, browser, and financial accounts. Reset exposed credentials as appropriate and require multifactor authentication where available. Do not assume that every credential was stolen.
  6. Preserve evidence and contain when warranted. Isolate endpoints with confirmed execution, suspicious communications, or other malicious activity. Preserve relevant evidence before wiping when incident-response, regulatory, or legal requirements apply.

What to do if you find an affected client

  1. Contain a suspicious endpoint. Follow your organization’s incident-response process to isolate it from networks and accounts where appropriate. If you have an MSP or security provider, involve them promptly and record the containment time.
  2. Remove the affected DesktopApp and use an approved alternative. During the incident, government guidance cited 3CX’s recommendation to uninstall the desktop client and use the browser-based Web App/PWA as a temporary alternative. See the Australian Cyber Security Centre alert. Confirm current product guidance before choosing a replacement now.
  3. Run updated endpoint scans and review EDR detections. Check related files, process activity, and network events, not just whether the application remains installed. Do not create broad antivirus exclusions simply to restore a client that security products have flagged.
  4. Decide whether credentials need resetting. Base the decision on evidence of execution and possible exposure, the accounts used on the endpoint, and your incident-response policy. Prioritize privileged and remote-access accounts.
  5. Escalate and rebuild if evidence warrants it. If there is confirmed execution plus suspicious post-exploitation activity, reimaging is generally more defensible than deleting a single file and declaring the endpoint clean. That is incident-response best practice, not a universal vendor-mandated step. A straightforward quarantined file with no execution or other indicators may call for a different response.

If you rely on an MSP, request an affected-device inventory, deployment and update logs, EDR detections, containment and remediation records, any credential-reset actions, confirmation that all relevant tenants were checked, and a timeline of exposure. If the incident involves likely lateral movement, regulated data, legal holds, or uncertain evidence, consider professional incident-response and forensic support.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why automatic updates were not the mistake

Automatic updates reduce the time users spend exposed to known flaws and make security fixes easier to deploy. Turning them off everywhere can leave software unpatched for longer. But an automatic update system can also distribute a compromised vendor build quickly, and code signing is not a guarantee that every signed program is benign.

Best Value
Sale
NexiGo N60 1080P Webcam with Microphone, Software Control & Privacy Cover, USB HD Computer Web Camera, Plug and Play, for Zoom/Skype/Teams, Conferencing and Video Calling
  • 【Full HD 1080P Webcam】Powered by a 1080p FHD two-MP CMOS, the NexiGo N60 Webcam produces exceptionally sharp and clear videos at resolutions up to 1920 x 1080 with 30fps. The 3.6mm glass lens provides a crisp image at fixed distances and is optimized between 19.6 inches to 13 feet, making it ideal for almost any indoor use.
  • 【Wide Compatibility】Works with USB 2.0/3.0, no additional drivers required. Ready to use in approximately one minute or less on any compatible device. Compatible with Mac OS X 10.7 and higher / Windows 7, 8, 10 & 11 / Android 4.0 or higher / Linux 2.6.24 / Chrome OS 29.0.1547 / Ubuntu Version 10.04 or above. Not compatible with XBOX/PS4/PS5.
  • 【Built-in Noise-Cancelling Microphone】The built-in noise-canceling microphone reduces ambient noise to enhance the sound quality of your video. Great for Zoom / Facetime / Video Calling / OBS / Twitch / Facebook / YouTube / Conferencing / Gaming / Streaming / Recording / Online School.
  • 【USB Webcam with Privacy Protection Cover】The privacy cover blocks the lens when the webcam is not in use. It's perfect to help provide security and peace of mind to anyone, from individuals to large companies. 【Note:】Please contact our support for firmware update if you have noticed any audio delays.
  • 【Wide Compatibility】Works with USB 2.0/3.0, no additional drivers required. Ready to use in approximately one minute or less on any compatible device. Compatible with Mac OS X 10.7 and higher / Windows 7, 10 & 11, Pro / Android 4.0 or higher / Linux 2.6.24 / Chrome OS 29.0.1547 / Ubuntu Version 10.04 or above. Not compatible with XBOX/PS4/PS5.

The practical lesson is not to disable updates across the board. Instead, combine timely patching with controls that limit the blast radius:

  • Keep an accurate inventory of software and where it is installed.
  • Use staged deployment or pilot rings for business-critical applications where the operational risk justifies it.
  • Maintain a tested rollback or removal plan for important software.
  • Monitor vendor advisories and EDR detections; investigate credible detections instead of dismissing them solely because a file is signed.
  • Use endpoint monitoring, application control, and identity protections alongside update mechanisms.
  • Apply extra change oversight to high-impact communications, identity, remote-access, and administrative tools without allowing that process to delay urgent security fixes indefinitely.

Automatic updates remain a useful security control. The 3CX incident showed why they should sit inside a broader security program that can inventory endpoints, detect unexpected behavior, and respond when a trusted source is compromised.

Current status and scope

This is a historical 2023 incident and a continuing supply-chain-security case study, not evidence of a newly emerging 3CX outbreak. The affected versions listed here are for historical identification. Organizations investigating old exposure should preserve and assess their own endpoint, network, and identity records; organizations making current software decisions should verify current 3CX guidance and their security provider’s advice. A clean or newer replacement client addresses the old software issue, but it does not by itself establish that an endpoint or account is safe.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.