所有厂商

Vendor lineage

3CX - the first cascading supply chain compromise

An employee's personal download of a retired trading app from another vendor became the way into the build servers of a telephony product with twelve million users.

3CX is a Cypriot developer of software telephone systems, founded in 2005, whose signed desktop application was used in March 2023 to deliver malware after a compromise that began at a different vendor.

3CX is a Cypriot software company, founded in Nicosia in 2005, whose product replaced the telephone exchange in the cupboard with software on a server. It sells only through the channel and by 2023 counted more than six hundred thousand customer organisations and twelve million users. It belongs in this catalogue for what happened in March of that year, which added a route to the taxonomy of supplier compromise that the other entries had not needed.

In March 2023 the company's own signed desktop application, delivered through its own update mechanism, began carrying malware to customers. That much had been seen before. What had not: when the incident responders traced the intrusion back into the company, they found it had begun with a different vendor's product. In 2022 an employee had downloaded, onto a personal computer, an installer for a trading application from another company. The application had been retired in 2020 but was still available on its maker's website, and the copy was trojanised - and signed with a certificate that was still valid. It opened the employee's machine, the corporate credentials on it were taken, and from there the intruders reached the build environments for both the Windows and Mac versions of the 3CX product. MITRE records it as the first publicly reported case of one supply chain compromise triggering another.

Three details are worth more than the sequence. The first is the retired product. Nobody at its maker was maintaining it, and it was still on the website carrying the company's name and the company's signature. A discontinued product is not a closed door; it is an unguarded one, and the Siemens entry's point about the installed base that cannot be updated has a software twin here in the download that nobody thought to remove.

The second is that the warning existed. A year before the 3CX incident surfaced, Google had published that the trading company's website had been compromised by the same operators. The information was public. The connection between a warning about one vendor and the exposure of another was not made, because nothing in either company's process was designed to make it - which is the Nortel entry's lesson, that an investigation stopped is not a threat gone, extended across a company boundary.

The third is the signature. Both the trojanised installer and the poisoned 3CX releases were legitimately signed. A code signature certifies that a build came from the pipeline it claims to have come from; it says nothing about whether the pipeline was the thing compromised. The XZ Utils entry makes the same point about the gap between what is reviewed and what is built. Here the gap was signed.

For the taxonomy this is a seventh route, and it differs in kind from the six: it is not a way in, but a way through. The routes compound. A vendor of trading software became the entrance to a vendor of telephony, whose customers were the target, and neither vendor was the point. When the intermediate vendor is merely a corridor, the question of whether one trusts it stops being about that vendor at all.

Sources