The 3CX DesktopApp Supply Chain Attack
Updated 5 Oct 2026 · Incident date 13 Mar 2023 · vendor binary
3CX Electron Desktop App: Windows 18.12.407 and 18.12.416; macOS 18.11.1213, 18.12.402, 18.12.407, 18.12.416ffmpeg.dllThe 3CX DesktopApp for Windows, versions 18.12.407 and 18.12.416, contained a trojanized library. The macOS builds 18.11.1213, 18.12.402, 18.12.407 and 18.12.416 were also affected. The attack became public on 29 March 2023, and the issue is tracked as CVE-2023-29059.
On Windows the bad file was ffmpeg.dll. It decrypted a hidden payload, then fetched instructions from the internet.
Major incident. Mandiant traced the 3CX intrusion to a compromised X_TRADER installer. Attackers then compromised the 3CX software build environment. Impact source
What happened
Signed 3CX installers carried malicious libraries. Unit 42 describes the Windows chain. The MSI installer puts the files in place and starts 3CXDesktopApp.exe. That program loads the bad ffmpeg.dll. The DLL reads an encrypted blob that hides inside d3dcompiler_47.dll and decrypts it with RC4.
The decrypted code then downloads icon files from a GitHub repository. Each icon file holds an encoded address, and the code extracts the command server address from it. It then contacts that server for a second-stage payload. Unit 42 reports that the first icon files appeared in the GitHub repository on 7 December 2022.
The macOS build used libffmpeg.dylib with 16 command server addresses built in. It did not use GitHub.
Unit 42 also reports that its Xpanse scans found 247,277 distinct IP addresses in 199 countries that ran 3CX applications. CrowdStrike attributed the activity to the group it calls Labyrinth Chollima, according to Unit 42. Fortinet notes that the file was a legitimate signed file that had been trojanized, and that 3CX revoked the certificates of the previous versions.
Affected versions
Unit 42, Fortinet and 3CX's advisory data agree on these versions.
- Windows: 3CXDesktopApp 18.12.407 and 18.12.416 (MSI installers)
- macOS: 18.11.1213, 18.12.402, 18.12.407 and 18.12.416 (DMG installers)
Fortinet recommends moving to the latest version. It names 18.12.422 for Windows as a fixed build. Fortinet also suggests the web-based PWA client as an alternative.
Indicators of compromise
ffmpeg.dllSHA-256:7986bbaee8940da11ce089383521ab420c443ab7b15ed42aed91fd31ce833896d3dcompiler_47.dllSHA-256:11be1803e2e307b647a8a7e02d128335c448ff741bf06bf52b332e0bbf423b03- Windows installer SHA-256:
aa124a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868 - macOS
libffmpeg.dylibSHA-1:769383fc65d1386dd141c960c9970114547da0c2 - macOS DMG 18.12.416 SHA-1:
3dc840d32ce86cebf657b17cef62814646ba8e98 - macOS files in the app folder:
UpdateAgent,.session-lockand.main-storage - Command domains include
glcloudservice.com,akamaitechcloudservices.com,azureonlinestorage.com,msedgepackageinfo.comandofficestoragebox.com. Unit 42 lists 15 in all. - Download of
icon1.icotoicon15.icofiles from GitHub by the 3CX app
How to check
Compare the hash of the DLL in your 3CX install folder with the value above. On Windows PowerShell:
Get-ChildItem -Path "$env:LOCALAPPDATA\Programs\3CXDesktopApp","C:\Program Files\3CXDesktopApp" -Recurse -Filter ffmpeg.dll -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA256
On macOS, look for the extra files that Fortinet names.
ls -la /Applications/3CX\ Desktop\ App.app/Contents/MacOS | grep -E "UpdateAgent|\.main-storage|\.session-lock"
Also search your DNS logs for the command domains.
What to do now
- Uninstall affected versions and install the latest 3CX build, or use the PWA client.
- Search your endpoints and logs for the hashes and domains above.
- If you find a match, isolate the host and treat it as compromised.
- Rotate credentials that were stored on or reachable from that host.
- Check network logs for connections to the command domains and to the GitHub icon files.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here ffmpeg.dll gained decrypt-and-run and download behavior. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 10 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED ffmpeg.dll It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
Which 3CX DesktopApp versions were compromised?
On Windows, 18.12.407 and 18.12.416. On macOS, 18.11.1213, 18.12.402, 18.12.407 and 18.12.416.
How do I check if 3CX DesktopApp was compromised?
Hash the ffmpeg.dll in the install folder and compare it with the published SHA-256 value. On macOS, look for UpdateAgent, .main-storage and .session-lock files in the app folder.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.