Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    GOP Sen. Dan Sullivan, Mary Peltola Advance In Alaska Primary

    August 20, 2026

    Fall 2026 on Maryland’s Eastern Shore: Best Season Yet

    August 20, 2026

    26 Beauty Secrets From Women Around The World

    August 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • GOP Sen. Dan Sullivan, Mary Peltola Advance In Alaska Primary
    • Fall 2026 on Maryland’s Eastern Shore: Best Season Yet
    • 26 Beauty Secrets From Women Around The World
    • Stripe didn’t really buy OpenRouter because of the ‘singularity’
    • Shiba Inu hype is returning, so why is Open Interest falling? – BitRss
    • Prosecutors: ‘No Serious Dispute’ Comey Seashell Post Could Be Read As Trump Threat
    • Woman Accused Of Plotting To Kill Treasury Secretary Sentenced
    • New Study Finds An Easy 3-Minute Habit Could Lower Your Cancer Risk
    Facebook X (Twitter)
    SBM Global News
    Demo
    • Home
    • Top Stories
      • Politics
    • Business
      • Small Business
      • Marketing
    • Finance
      • Investment
    • Technology

      Stripe didn’t really buy OpenRouter because of the ‘singularity’

      August 20, 2026
      Read More

      Mitti (by SafetyCulture) – Company Profile

      August 19, 2026
      Read More

      Comcast adds motion sensing to millions of its newer routers, with a privacy catch

      August 19, 2026
      Read More

      GLESEC – Company Profile – AllBusiness.com

      August 18, 2026
      Read More

      Stripe will reportedly acquire AI gateway startup OpenRouter for $7B+

      August 17, 2026
      Read More
    • Lifestyle
      • Travel
    • Feel Good
    • Get In Touch
    SBM Global News
    Demo
    Home»Technology»3CX’s supply chain attack was caused by… another supply chain attack
    Technology

    3CX’s supply chain attack was caused by… another supply chain attack

    By Staff WriterApril 20, 20233 Mins Read
    Facebook Twitter LinkedIn Reddit Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The incident responders investigating how hackers carried out a complex supply-chain attack targeting enterprise phone provider 3CX say the company was compromised by another supply chain attack.

    3CX, which develops a software-based phone system used by over 600,000 organizations worldwide with more than 12 million active daily users, worked with cybersecurity company Mandiant to investigate the incident. In its report released on Thursday, Mandiant said that attackers compromised 3CX using a malware-laced version of the X_Trader financial software, developed by Trading Technologies.

    X_Trader was a platform used by traders to view real-time and historical markets, which Trading Technologies phased out in 2020, but Mandiant says was still available to download from the company’s website in 2022.

    Mandiant said it suspects the Trading Technologies website was compromised by a group of North Korea state-backed hackers, which it refers to as UNC4736.

    This is backed up by a report from Google’s Threat Analysis Group from last year, which confirmed that Trading Technologies’ website was compromised in February 2022 as part of a North Korean operation targeting dozens of cryptocurrency and fintech users. U.S. cybersecurity agency CISA says the hacking group has used its custom “AppleJeus” malware to steal cryptocurrency from victims in over 30 countries.

    Mandiant’s investigation found that a 3CX employee downloaded a tainted version of the X_Trader software in April 2022 from Trading Technologies’ website, which the hackers had digitally signed with the company’s then-valid code signing certificate to make it look as if it was legitimate.

    Once installed, the software planted a backdoor on the employee’s device, giving the attackers full access to the compromised system. This access was then used to move laterally through 3CX’s network and, eventually, to compromise 3CX’s flagship desktop phone app to plant information-stealing malware inside their customers’ corporate networks.

    “This is notable to us because this is the first time we’ve ever found concrete evidence of a software supply chain attack leading to another supply chain attack,” said Mandiant’s chief technology officer Charles Carmakal. “This series of coupled supply-chain attacks just illustrates the increasing cyber offensive cyber capability by North Korean threat actors.”

    Mandiant says it notified Trading Technologies about the compromise on April 11 but says it’s not known how many users are affected.

    Trading Technologies spokesperson Ellen Resnick told TechCrunch that the company has not yet verified Mandiant’s findings, and reiterated that it stopped supporting the software in 2020.

    Mandiant’s Carmakel added that it’s likely “many more victims” related to the two supply-chain attacks will become known in the coming weeks and months.

    3CX blames North Korea for supply chain mass-hack

    3CX’s supply chain attack was caused by… another supply chain attack by Carly Page originally published on TechCrunch

    Originally published at techcrunch.com

    Demo
    devices gadgets notebooks phones tablets technology
    Share. Facebook Twitter LinkedIn Email Reddit
    Previous ArticleCredit Agency Giant TransUnion Starts Delivering Credit Scores for Crypto Lending
    Next Article Peering Into the Future of Novels, With the Help of AI

    Related Posts

    Stripe didn’t really buy OpenRouter because of the ‘singularity’

    August 20, 2026
    Read More

    Mitti (by SafetyCulture) – Company Profile

    August 19, 2026
    Read More

    Comcast adds motion sensing to millions of its newer routers, with a privacy catch

    August 19, 2026
    Read More
    Add A Comment

    Leave A Reply Cancel Reply

    Demo
    Top Posts

    Former FBI, CIA Head Has ‘Serious Concerns’ With Trump Cabinet Picks

    December 28, 2024435

    Emirates to operate next-gen A350 on the third daily service to Cape Town

    January 14, 2026256

    AAVE Price Prediction: Target $215-225 by Mid-January 2025 as Technical Indicators Signal Bullish Momentum

    December 15, 2025240

    Ventive Hospitality Joins Green Fins: Strong ESG Lift

    February 17, 2026211
    Don't Miss
    Politics

    GOP Sen. Dan Sullivan, Mary Peltola Advance In Alaska Primary

    By Staff WriterAugust 20, 20263 Mins Read

    CORRECTION: Dan Sullivan of Petersburg could still advance to the general election, as the top…

    Read More

    Fall 2026 on Maryland’s Eastern Shore: Best Season Yet

    August 20, 2026

    26 Beauty Secrets From Women Around The World

    August 20, 2026

    Stripe didn’t really buy OpenRouter because of the ‘singularity’

    August 20, 2026
    Stay In Touch
    • Facebook
    • Twitter
    Demo
    About Us

    Small Business Minder brings together business and related news from around the world in one place. Follow us for all the business news you'll need.

    Facebook X (Twitter)
    Our Picks

    GOP Sen. Dan Sullivan, Mary Peltola Advance In Alaska Primary

    August 20, 2026

    Fall 2026 on Maryland’s Eastern Shore: Best Season Yet

    August 20, 2026
    Most Popular

    Former FBI, CIA Head Has ‘Serious Concerns’ With Trump Cabinet Picks

    December 28, 2024435

    Emirates to operate next-gen A350 on the third daily service to Cape Town

    January 14, 2026256
    © 2026 Small Business Minder
    • Home
    • Get In Touch

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. To get the most from our site, please disable your Ad Blocker.