Alert:

We have become aware that an Active Intrusion Campaign targeting the 3CX Desktop App has now been detected. It has been advised that users with the affected Desktop Application take immediate action.

Mitigation Action:

The following steps could assist resellers in mitigating this issue until there is a formal response and resolution from 3CX.

  1. Remove the affected desktop application from all end-user systems.
  2. Remove the installation files from the 3CX instance they are located in /var/lib/3cxpbx/Instance1/Data/Http/electron/windows/
  3. Download the following zip file from https://3cx.ucreseller.co.uk/windows.zip 
  4. Copy the files onto the 3CX instance in the following folder /var/lib/3cxpbx/Instance1/Data/Http/electron/windows/
  5. Please note that these files have been renamed to look like u7 files but are, in fact, u5 files. We believe the affected files are 18.12.416; the files included within the ZIP are 18.10.461.
  6. You can then download the client from the web app and provision the extension.

Or

You could remove the desktop application from all end-user systems and use the web app until there is a response and resolution from 3CX.

3CX Responses:

30/03/2023 – 6:27 AM Nick Galea wrote:

Hi

 

As many of you have noticed the 3CX DesktopApp has a malware in it. It affects the Windows Electron client for customers running update 7. It was reported to us yesterday night and we are working on an update to the DesktopApp which we will release in the coming hours.

 

The best way to go about this is to uninstall the app (if you are running Windows Defender, its going to do this automatically for you unfortunately) and then install it again. We are going to analyze and issue a full report later on today. Right now we are just focusing on the update.

 

We strongly recommend using our PWA client instead. It really does 99% of the client app and is fully web based and this type of thing can never happen. Only thing you dont have is hotkeys and BLF. But in light of what happened yesterday we are going to address BLF immediately and hotkeys if we can.

 

So please use PWA for the moment until we release a new build. And consider using PWA instead of Electron.

 

Furthermore my team and myself apologize profusely for this issue.

 

Relevant links on the 3CX Blog:

30/03/2023 – https://www.3cx.com/blog/news/desktopapp-security-alert/

Relevant links on the 3CX forum:

https://www.3cx.com/community/threads/threat-alerts-from-sentinelone-for-desktop-update-initiated-from-desktop-client.119806/ 

https://www.3cx.com/community/threads/crowdstrike-endpoint-security-detection-re-3cx-desktop-app.119934/

https://www.3cx.com/community/threads/3cx-desktop-app-vulnerability-security-group-contact.119930/ 

https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/

Further Reading:

 

// 2023-03-29 // SITUATIONAL AWARENESS // CrowdStrike Tracking Active Intrusion Campaign Targeting 3CX Customers //
by u/Andrew-CS in crowdstrike

3CX likely comprised, take action.
by u/12bsod in msp

Relevant links on other websites:

https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/ 

https://www.halosync.io/blog/security-warning-3cx-customers 

https://threatlocker.com/blog/cybersecurity-in-the-news-unconfirmed-3cx-desktop-app-compromise 

 

 

Share This