On 20 April 2023 Mandiant reported the initial intrusion vector for the 3CX compromise. The route was X_TRADER, trading software from Trading Technologies: an installer downloaded from the vendor’s own website carried malware tracked as VEILEDSIGNAL, which established persistence on a 3CX employee’s personal computer. The activity was attributed to UNC4736, associated with North Korean operations.
Mandiant described it as the first time it had seen one software supply chain attack lead to another. This corpus filed the downstream half at 23-0329.
The Chain Has More Than One Link
Supply chain compromise is usually filed as a two-party relationship: a vendor is breached, and the vendor’s customers inherit it. That framing survives right up to the point where the breached vendor was itself reached through another vendor’s product.
We have recorded the two-party version at 24-1121 and 26-0717. What this file adds is depth — an assessment of a supplier that stopped at the supplier’s own controls would have found nothing, because the relevant exposure was one more step back and in an unrelated industry. Nobody assessing a phone-system vendor asks about its staff’s trading software.
The Download Was Legitimate
The employee did nothing careless. They obtained software from the vendor’s official website, which is the exact behaviour every security programme instructs people to follow.
We have recorded the same collapse of user-side advice at 22-0527, where a document needed no macro, and at 22-0808, where three people who clicked were saved by a control rather than by judgement. Guidance that reduces to "obtain software from the official source" has no answer when the official source is the compromise.
A Personal Computer, Again
The infected machine was the employee’s own. That is the third file in this corpus where the corporate perimeter turned out to include a personal device: 22-1222, where a home computer running media software led to every LastPass vault, and 22-0524, where a personal Google account held synced corporate credentials.
Trading software on a personal machine is not a category any corporate control covers, and we have recorded at 26-0703 that the remote-access boundary is where three quarters of intrusions arrive. This is what that boundary looks like when drawn honestly.
Compiled from Mandiant’s 20 April 2023 findings, 3CX’s own security update publishing them, and contemporaneous reporting, listed below. Attribution is carried as the researchers’ assessment rather than as established fact. The downstream 3CX compromise is filed separately at 23-0329 and its figures are not restated here. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.