Desk live·
ForensicPost
Nation-state/Supply chain/File 23-0329

Mandiant Says One Supply Chain Compromise Caused Another at 3CX

A 3CX employee installed a tampered trading application. That backdoor reached the build server, and 3CX then shipped signed desktop software carrying malware to its own customers. Mandiant described it as the first time it had seen one software supply chain attack produce a second.

Constructed geometry · not a chart of case data
Target3CX
ActorUNC4736
D. Kennedy12 min readConfidence: high2 sources reviewed

In March 2023 the 3CX desktop application was found to be shipping with malicious code. Legitimately signed Windows and macOS builds, delivered through the vendor’s own update mechanism, carried malware to downstream customers.

Mandiant’s investigation traced the initial access to a different compromise entirely: an employee had downloaded a tampered version of X_TRADER, a financial trading application, which deployed a backdoor Mandiant named VEILEDSIGNAL. Credentials taken from that machine led to the 3CX build environment.

The Signature Was Valid

Code signing answers the question "did this come from the vendor". Here the answer was yes, and it was the wrong question. The vendor’s own build process produced the malicious artefact and signed it, exactly as designed.

The corpus files the same failure of a trust primitive at 23-0711, where a forged token was signed with a key the platform trusted. In both cases the control did not break; it faithfully attested to something the attacker had already arranged.

A Chain Of Two

The structural novelty is the composition. Supply chain risk is usually modelled one hop deep — an organisation asks what its suppliers do. Here the compromise arrived from a piece of unrelated software installed by one employee, and travelled outward through a product used by organisations that had no relationship with the first vendor at all.

The corpus later records related shapes at 25-0717 for the AsyncAPI npm compromise and 25-0711 for jscrambler, both of which target the build machine rather than the product. The build machine is where a single compromise becomes everyone’s compromise.

Attribution, And What It Does Not Change

Mandiant assessed with high confidence that the cluster it tracks as UNC4736 has a North Korean nexus, and 3CX confirmed that assessment publicly. This desk records that as the investigators’ assessment.

It changes the geopolitics and it changes nothing operational. No defensive decision available to a 3CX customer depended on who was behind it.

How we reported this

Built on Mandiant’s published account of the 3CX compromise and on contemporaneous reporting of the X_TRADER origin and the vendor’s confirmation. The X_TRADER chain, the VEILEDSIGNAL backdoor and the UNC4736 cluster are Mandiant’s findings and naming, reported as such. The North Korean nexus is Mandiant’s assessment, publicly accepted by 3CX; it is not an independent finding of this desk. No count of affected downstream customers is asserted — none was established. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain CompromiseMandiant / Google Cloud
  2. 3CX confirms North Korean hackers behind supply chain attackBleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary