
VoIP IPBX software development company 3CX, which has more than 600,000 companies and over 12 million daily users worldwide, has revealed a digitally signed and trojanized version of its 3CX Voice Over Internet Protocol (VOIP) desktop client is being used by hackers to target its customers, which include a long list of high-profile companies.
The disclosure came after multiple cybersecurity vendors raised the alarm about what appears to be an active supply chain attack targeting downstream customers using a trojanized version of the popular voice and video conferencing software.
Security researchers from Sophos and CrowdStrike claim that the hacked 3CX softphone app’s attackers are aiming their attacks at both Windows and macOS users. Malicious activity includes deploying second-stage payloads, beaconing to actor-controlled infrastructure, and using the keyboard directly in a few instances.
The spawning of an interactive command shell has been noted as the most frequent post-exploitation activity to date, according to a statement made by Sophos and distributed through its Managed Detection and Response service.
CrowdStrike believes this attack is the work of Labyrinth Collima, a North Korean state-backed hacking group. However, Sophos researchers say they cannot confirm this attribution with certainty. Labyrinth Collima’s activity overlaps with other threat actors, including the Lazarus Group of Kaspersky, the Covellite of Dragos, the UNC4034 of Mandiant, the Zinc of Microsoft, and the Nickel Academy of Secureworks.
SentinelOne and Sophos revealed in reports published Thursday evening that they are tracking the malicious activity under the name “SmoothOperator.” The threat actor seemingly registered a massive attack infrastructure as far back as February 2022, and there are indications that the attack began around March 22, 2023, reports suggested. This new malware can steal data and stored credentials from Chrome, Edge, Brave, and Firefox user profiles.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543