Security News > 2023 > April > Critical infrastructure also hit by supply chain attack behind 3CX breach

The X Trader software supply chain attack that led to last month's 3CX breach has also impacted at least several critical infrastructure organizations in the United States and Europe, according to Symantec's Threat Hunter Team.
While the Trading Technologies supply chain compromise is the result of a financially motivated campaign, the breach of multiple critical infrastructure organizations is worrisome, seeing that North Korean-backed hacking groups are also known for cyber espionage.
It's very likely that strategic organizations compromised as part of this supply chain attack will also be singled out for subsequent exploitation.
"The discovery that 3CX was breached by another, earlier supply chain attack made it highly likely that further organizations would be impacted by this campaign, which now transpires to be far more wide-ranging than originally believed," Symantec added.
"The attackers behind these breaches clearly have a successful template for software supply chain attacks and further, similar attacks cannot be ruled out."
On Thursday, Mandiant linked a North Korean threat group it tracks as UNC4736 to the cascading supply chain attack that hit VoIP company 3CX in March.
News URL
Related news
- It's only a matter of time before LLMs jump start supply-chain attacks (source)
- CISA warns of critical Oracle, Mitel flaws exploited in attacks (source)
- Hackers exploit critical Aviatrix Controller RCE flaw in attacks (source)
- Critical SimpleHelp Flaws Allow File Theft, Privilege Escalation, and RCE Attacks (source)
- PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack (source)
- IPany VPN breached in supply-chain attack to push custom malware (source)
- Supply chain attack hits Chrome extensions, could expose millions (source)
- Zyxel CPE devices under attack via critical vulnerability without a patch (CVE-2024-40891) (source)
- Abandoned AWS S3 buckets can be reused in supply-chain attacks that would make SolarWinds look 'insignificant' (source)
- Critical RCE bug in Microsoft Outlook now exploited in attacks (source)