The threat actor — believed to be the Lazarus Group — that recently compromised 3CX's VoIP desktop application to distribute information-stealing software to the company's customers has also dropped a ...
The supply chain attack on the 3CX voice-calling app has been traced back to a company employee installing a legitimate, but malware -laden program, onto their personal computer. The findings come ...
‘This is the first time Mandiant has seen a software supply chain attack lead to another software supply chain attack,’ the firm said in a post Thursday. Prominent cyberattack investigator Mandiant ...
The disclosure appears to confirm an earlier attribution by CrowdStrike to a group working on behalf of North Korea’s government. Mandiant has attributed the 3CX supply chain compromise with “high ...
VoIP communications company 3CX confirmed today that a North Korean hacking group was behind last month's supply chain attack. "Based on the Mandiant investigation into the 3CX intrusion and supply ...