3CX DesktopApp Targeted in Active Intrusion Campaign
Alert:
We have become aware that an Active Intrusion Campaign targeting the 3CX Desktop App has now been detected. It has been advised that users with the affected Desktop Application take immediate action.
Mitigation Action:
The following steps could assist resellers in mitigating this issue until there is a formal response and resolution from 3CX.
- Remove the affected desktop application from all end-user systems.
- Remove the installation files from the 3CX instance they are located in /var/lib/3cxpbx/Instance1/Data/Http/electron/windows/
- Download the following zip file from https://3cx.ucreseller.co.uk/windows.zip
- Copy the files onto the 3CX instance in the following folder /var/lib/3cxpbx/Instance1/Data/Http/electron/windows/
- Please note that these files have been renamed to look like u7 files but are, in fact, u5 files. We believe the affected files are 18.12.416; the files included within the ZIP are 18.10.461.
- You can then download the client from the web app and provision the extension.
Or
You could remove the desktop application from all end-user systems and use the web app until there is a response and resolution from 3CX.
3CX Responses:
30/03/2023 – 6:27 AM Nick Galea wrote:
Relevant links on the 3CX Blog:
30/03/2023 – https://www.3cx.com/blog/news/desktopapp-security-alert/
Relevant links on the 3CX forum:
https://www.3cx.com/community/threads/3cx-desktop-app-vulnerability-security-group-contact.119930/
https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/
Further Reading:
// 2023-03-29 // SITUATIONAL AWARENESS // CrowdStrike Tracking Active Intrusion Campaign Targeting 3CX Customers //
by u/Andrew-CS in crowdstrike
Relevant links on other websites:
https://www.halosync.io/blog/security-warning-3cx-customers
https://threatlocker.com/blog/cybersecurity-in-the-news-unconfirmed-3cx-desktop-app-compromise
Recent Comments