What is 3CXDesktop App?
3CXDesktopApp is a desktop client of 3CX voice over IP (VoIP) system. The application allows users to communicate within and outside the organization through their desktop or laptops.
The app can record calls and facilitate video conferencing and can be used on Windows, macOS, and Linux operating systems. It’s a tool that businesses use when they have a hybrid or remote workforce and their customers include government service providers like the NHS as well as large enterprises including Coca-Cola, Ikea and Honda.
What happened?
Over the past few days there has been accumulated evidence a Trojanized version of the original 3CXDesktopApp client is being downloaded to unsuspecting victims around the world. The Trojanized version includes a malicious DLL file, which replaced an original one, which is known to come with the benign version of the app. Then, when the application is loaded, the signed 3CXDesktopApp is executing the malicious DLL as part of its predefined execution procedure.
This turned the innocent popular VoIP app into a full blown malware that beacons to remote servers and capable of running second stage malware.
Supply chain attack indeed
This is a classic supply chain attack, although there is no evidence as of the time of writing this initial report, that there is any intervention in the source code of 3CXDesktopApp. And yet, no one expected the application to be served with a malicious implant.
Supply chain attacks are designed to exploit trust relationships between an organization and external parties. These relationships could include partnerships, vendor relationships, or the use of third-party software. Cyber threat actors will compromise one organization and then move up the supply chain, taking advantage of these trusted relationships to gain access to other organizations’ environments.
This joins the weaponization of legitimate tools
The basic layer of cyber protection is recognizing malicious tools and behaviors before they can strike. Security vendors invest substantial resources in the research and mapping of malware types and families, and their attribution to specific threat actors and the associated campaigns, while also identifying TTPs (Techniques, Tactics and Procedures) that inform the correct security cycles and security policy.
To combat sophisticated cybersecurity solutions, threat actors are developing and perfecting their attack techniques, which increasingly rely less on the use of custom malware and shift instead to utilizing non-signature tools. They use built-in operating system capabilities and tools, which are already installed on target systems, and exploit popular IT management tools that are less likely to raise suspicion when detected. Commercial off-the-shelf pentesting and Red Team tools are often used as well. Although this is not a new phenomenon, what was once rare and exclusive to sophisticated actors has now become a widespread technique adopted by threat actors of all types.
Protection- Check Point Software Customers remain protected
Supply chain attacks are one of the most complex attack forms. Security vendors cannot rely solely on reputation based or single layered solutions. They need to question activity as seen in the network, endpoints, servers and to connect the dots.
Check Point Horizon XDR/XPR is designed to provide comprehensive threat prevention across the entire security estate, with Check Point’s Infinity architecture.
The platform immediately blocks cyber threats originating in any part of the environment and prevents them from impacting the org and propagating across additional entities. XDR/XPR represents your last line of cyber defense; an additional layer of security across your consolidated security estate. Check Point Horizon XDR/XPR prevents complex attacks where seemingly benign events across different parts of the security estate, add up to a critical threat to your organization. The platform can automatically stop threats from propagating and spreading within your organization, and provides clear forensics as extra validation for the SecOps user.
All software vulnerabilities and attack signatures that are found by Check Point Research (CPR) or seen in the wild, such as the Trojanized version of the original 3CXDesktopApp, are immediately fed to Check Point’s ThreatCloud, the brain behind all of Check Point’s products, which propagates the appropriate protections throughout Check Point’s products, so that all Check Point customers are instantly protected with no patching needed.