Does Confluence use 3CXDesktop VoIP Software (video-conf app) which has known vulnerabilities?

pinny.tam April 5, 2023

On Wednesday, March 29, 2023, multiple security firms issued warnings about malicious activity coming from a legitimate, signed binary from communications technology company 3CX. The binary, 3CXDesktopApp, is video conferencing software available for download on all major platforms. Rapid7’s threat research teams analyzed the Windows installer and confirmed that it is downloading and executing malicious DLL files. A suspected North Korean threat actor dubbed Labyrinth Chollima gained access to and backdoored the software distribution process for 3CX. This supply chain attack known as 'SmoothOperator' leverages malicious access that was delivered to customers through the auto-update mechanism of the software.

https://www.bleepingcomputer.com/news/security/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/

https://www.cisa.gov/news-events/alerts/2023/03/30/supply-chain-attack-against-3cxdesktopapp

1 answer

0 votes
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
April 5, 2023

This has nothing to do with Confluence, unless you've decided to install it on the same server and do some integration with it for some reason.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
TAGS
AUG Leaders

Atlassian Community Events