Skip to content

Malware

3CX Backdoor

aka SUDDENICON

According to CrowdStrike, this backdoor was discovered being embedded in a legitimate, signed version of 3CXDesktopApp, and thus constitutes a supply chain attack.

3CX Backdoor, also known as SUDDENICON, is a Windows malware family operated by Lazarus Group.

Background

CrowdStrike reports that this backdoor was found planted inside a legitimate, signed build of 3CXDesktopApp, making the incident a supply chain attack.


Source: Malpedia (Fraunhofer FKIE).