Could it be that the reason is not the hack but bad credentials? Since several weeks we can see dozens of login attempts to all of our systems, often it's the same ip that tries to login on the webclient. In the eventlog you can see the passwords they try to use, and to be honest, it's not a real bruteforce attack it's mainly simple password lists like Start1234 and so on. Was the password of the compromised account complex or was it very basic?I'm trying again, without screenshot that shows the attackers ip
This weekend attackers gained access to our pbx using stolen credentials of a user with management console privileges:
- they enabled every kind of international calls
- they disabled all notifications
- they made a lot of calls to "international networks" prefix +882 and several others
- made a bunch of outbound rules
- custom modified an extension
- maybe the downloaded backups (why doesn't the audit show if someone downloads a backup?? tried myself, doesn't show)
It's an attack 100%Could it be that the reason is not the hack but bad credentials? Since several weeks we can see dozens of login attempts to all of our systems, often it's the same ip that tries to login on the webclient. In the eventlog you can see the passwords they try to use, and to be honest, it's not a real bruteforce attack it's mainly simple password lists like Start1234 and so on. Was the password of the compromised account complex or was it very basic?
Yes, it's an attack but theese kinds of attacks were always there. Open Port 5001 and the bots try to login, open port 22 facing the internet and some bots try to login via ssh. I don't say that's not an attack but that's nothing special when opening ports to the internet. Also with 3cx theese attempts were always there, but with the new group rights there is the risk that someone can change admin settings.It's an attack 100%
- Calls were made to international destinations
- settings were modified to do this
i have the audit showing connections form Ukraine, France , UK, same user
Her is what i mean, in 18.6 you could see the login attempts
View attachment 34989
that's no complex attack, that's simple password trying
What happened was:It seems you had a colleague who had the compromised 3CX client on their computer and potentially saved credentials in for all three clients. Or are you saying that this colleague went onsite and plugged their laptop into the office and the attackers in that time figured out where the non-3CX cloud PBX was for that customer? It may be related or it could be conjecture. I recommend having said colleague run the Thor scanner linked in the forum for proof that the second stage was activated and then go from there. I would also recommend not storing passwords in the browser and changing any other client passwords that may have been accessed.
I've had the same thing happen once in the past (long before the recent attack) where one of our extensions was making a large number of international calls at strange hours. Our carrier flagged it as suspicious activity and temporarily disabled international calling for us. It turned out to be a compromised extension that had a weak auth username and password. It's understandable why 3CX now requires these to be stronger.What happened was:
- we received a warning form our provider for suspicious traffic
- we checked the numbers, first 2 numbers were related to clients with a frepbx based pbx, both were visited by the same colleague in the last week of march
- the other numbers were from our cloud 3CX which an attacker gained access to a user with management console rights
Plase note that i just want to share what happened and see if anyone else had the same problem after what happened, if our case is isolated that's for the best
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.