Vendor lineage
3CX - the first cascading supply chain compromise
An employee's personal download of a retired trading app from another vendor became the way into the build servers of a telephony product with twelve million users.
3CX is a Cypriot developer of software telephone systems, founded in 2005, whose signed desktop application was used in March 2023 to deliver malware after a compromise that began at a different vendor.
3CX is a Cypriot software company, founded in Nicosia in 2005, whose product replaced the telephone exchange in the cupboard with software on a server. It sells only through the channel and by 2023 counted more than six hundred thousand customer organisations and twelve million users. It belongs in this catalogue for what happened in March of that year, which added a route to the taxonomy of supplier compromise that the other entries had not needed.
In March 2023 the company's own signed desktop application, delivered through its own update mechanism, began carrying malware to customers. That much had been seen before. What had not: when the incident responders traced the intrusion back into the company, they found it had begun with a different vendor's product. In 2022 an employee had downloaded, onto a personal computer, an installer for a trading application from another company. The application had been retired in 2020 but was still available on its maker's website, and the copy was trojanised - and signed with a certificate that was still valid. It opened the employee's machine, the corporate credentials on it were taken, and from there the intruders reached the build environments for both the Windows and Mac versions of the 3CX product. MITRE records it as the first publicly reported case of one supply chain compromise triggering another.
Three details are worth more than the sequence. The first is the retired product. Nobody at its maker was maintaining it, and it was still on the website carrying the company's name and the company's signature. A discontinued product is not a closed door; it is an unguarded one, and the Siemens entry's point about the installed base that cannot be updated has a software twin here in the download that nobody thought to remove.
The second is that the warning existed. A year before the 3CX incident surfaced, Google had published that the trading company's website had been compromised by the same operators. The information was public. The connection between a warning about one vendor and the exposure of another was not made, because nothing in either company's process was designed to make it - which is the Nortel entry's lesson, that an investigation stopped is not a threat gone, extended across a company boundary.
The third is the signature. Both the trojanised installer and the poisoned 3CX releases were legitimately signed. A code signature certifies that a build came from the pipeline it claims to have come from; it says nothing about whether the pipeline was the thing compromised. The XZ Utils entry makes the same point about the gap between what is reviewed and what is built. Here the gap was signed.
For the taxonomy this is a seventh route, and it differs in kind from the six: it is not a way in, but a way through. The routes compound. A vendor of trading software became the entrance to a vendor of telephony, whose customers were the target, and neither vendor was the point. When the intermediate vendor is merely a corridor, the question of whether one trusts it stops being about that vendor at all.
- Mandiant, 20 April 2023: responding to the March 2023 compromise of the 3CX Desktop App, Mandiant identified that the initial vector into 3CX's network was malicious software downloaded from Trading Technologies' website - the first time Mandiant had seen a software supply chain attack lead to another software supply chain attack; the actor is tracked as UNC4736, a suspected North Korean cluster
- MITRE ATT&CK campaign C0057: the first publicly reported case of one supply chain compromise triggering another. A 3CX employee downloaded and executed a trojanised, end-of-life version of the X_Trader trading software; from that foothold UNC4736 compromised the Windows and macOS build environments used to distribute the 3CX desktop application. 3CX serves more than 600,000 customers and 12 million users; only a subset of systems were affected
- SecurityWeek on the mechanism: X_Trader had been retired in 2020 but was still available on the vendor's website; the malicious version, downloaded by the employee onto a personal computer sometime in 2022, was signed with a certificate valid until October 2022; it delivered the VeiledSignal backdoor, which gave administrator access to the device and allowed corporate credentials to be taken. Google had reported in March 2022 that the Trading Technologies website had been compromised by North Korean actors
- Dark Reading, quoting Mandiant's lead investigator: Mandiant observed evidence of compromise of the Trading Technologies environment as far back as 2021, and after the 3CX employee's computer was compromised in 2022 the actor stole the employee's corporate credentials; multiple vendors observed legitimately signed Windows and Mac versions of the 3CX app reaching customers bundled with malicious installers
- 3CX company page: founded in 2005 in Nicosia by Nick Galea, developer of a software PBX on open SIP standards, a wholly channel-based company