Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The March 2023 3CX attack was a cascading supply-chain compromise: attackers used a trojanized X_TRADER installer to gain an initial foothold, then compromised 3CX build environments and distributed malicious versions of its desktop app. Mandiant assessed with high confidence that the activity had a North Korean nexus; later campaign reporting described targeting focused on cryptocurrency and defense organizations. That does not mean every 3CX customer—or every cryptocurrency firm—was compromised.
How the attack reached 3CX customers
The compromise unfolded in two linked stages. The first targeted software made by Trading Technologies; the second abused 3CX’s own software production and distribution path. MITRE describes this as the first publicly reported case of one supply-chain compromise triggering another, a characterization attributable to MITRE rather than a universal historical claim.
| Stage | What happened | Why it mattered |
|---|---|---|
| Upstream entry | Mandiant reported that a 3CX employee installed X_TRADER on a personal computer. The installer, downloaded from Trading Technologies’ website, contained VEILEDSIGNAL malware. MITRE dates the campaign’s first sighting to November 2022. Mandiant’s account and MITRE’s campaign record describe this initial path. | The attackers used a compromised third-party application to gain a route into the 3CX environment. |
| Downstream distribution | Using that access, attackers compromised 3CX Windows and macOS build environments. Malicious code then reached customers through legitimate-looking 3CX desktop software. MITRE summarizes the build compromise; CrowdStrike observed malicious activity from the legitimate, signed 3CXDesktopApp binary. | Because the app was signed and distributed through the vendor’s channel, the attack could appear to come from trusted software rather than an obviously suspicious download. |
On March 29, 2023, 3CX said it received third-party reports of a possible security issue. The next day, CISA relayed reports that trojanized 3CXDesktopApp software could lead to multistage attacks. CrowdStrike reported observing beaconing and deployment of second-stage payloads on Windows and macOS. These observations establish malicious activity associated with the app; they do not establish that every installation was infected. 3CX’s incident updates, CISA’s March 30 advisory, and CrowdStrike’s report document the incident-period findings.
Did the attack target cryptocurrency companies?
Campaign reporting describes cryptocurrency and defense organizations as subsequent targeting priorities. This is narrower than saying all 3CX customers were targets or that every organization in those sectors was breached. MITRE says only a subset of 3CX systems were affected and describes the later sector focus in its campaign record.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
MITRE’s record, created August 25, 2025 and checked October 4, 2026, says 3CX served more than 600,000 customers and 12 million users. Those figures describe the platform’s reach, not the number of infected systems or confirmed victims. The available reporting does not establish a verified total of cryptocurrency firms successfully compromised or a complete financial-loss figure.
What “exposed” means—and what it does not
Having an affected 3CX build means a system may have been exposed to the malicious software. Confirmed compromise is a stronger claim: it requires evidence such as malicious execution or downstream activity. The distinction matters because reports of a compromised distribution channel do not show that every recipient ran the malware, nor that all exposed machines were successfully exploited. MITRE explicitly notes that only a subset of 3CX systems were affected.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
What investigators concluded about attribution
In its April 11, 2023 update, 3CX said Mandiant attributed the activity to UNC4736 and assessed with high confidence that the cluster had a North Korean nexus. Mandiant’s public account discusses the intrusion vector and actor assessment. 3CX’s summary of Mandiant’s interim findings and Mandiant’s report provide the basis for that qualified attribution.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Other organizations used different tracking labels: CrowdStrike connected its observations to LABYRINTH CHOLLIMA, while MITRE associates the campaign with AppleJeus. These are separate organizations’ analytical labels, not proof that publicly identified individuals carried out the attack or that the names are perfectly interchangeable. CrowdStrike and MITRE state their respective terminology.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Malware and platform details reported during the investigation
In its April 11 update, 3CX described TAXHAUL/TxRLoader on Windows, a downloader called COLDCAT, and the SIMPLESEA backdoor on macOS. It also cautioned that TAXHAUL’s subsequent malware differed from GOPURAM discussed in Kaspersky reporting. Those names describe specific components reported during the investigation; they should not be collapsed into one payload or treated as evidence that every affected endpoint received every component. 3CX’s update gives the distinctions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What 3CX and CISA advised at the time
These were incident-period instructions, not a current alert. On April 1, 2023, 3CX advised Windows and Mac users to remove its Electron Desktop App, continue antivirus scans and endpoint detection and response work with current signatures, and use its progressive web app (PWA) client instead. CISA urged organizations to consult technical reporting and hunt for the listed indicators of compromise. CrowdStrike likewise recommended removing the software until the vendor advised that later installers or builds were safe. See 3CX’s dated guidance, CISA’s advisory, and CrowdStrike’s recommendations.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
For a present-day incident, organizations should verify the current vendor advisory and the exact installed version before acting on historical removal guidance. If investigating possible exposure, preserve relevant endpoint and network evidence and follow current advice from the vendor and appropriate incident-response authorities.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

