Product
3CX
- First Reported
- Dec 17, 2025
- Latest Reported
- Dec 17, 2025
Reported Context (1)
- analysis, the ELF exhibits similar behavior to the BADCALL backdoor that was previously seen in the 3CX supply chain attack by Lazarus. One of these, 23.27.177[.]183, appears in Hunt.io IP intelligence as Hunt.io and Acronis Trace Lazarus and Kimsuky Infrastructure Across Campaigns
Malware (6)
People (1)
Threat Actors (4)
MITRE ATT&CK (3)
Vendors (2)
Tools (29)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.