Our pbx was taken over this weekend

Status
Not open for further replies.

mike9055

Premier Customer
Advanced Certified
Joined
Dec 2, 2022
Messages
84
Reaction score
43
edit: my post is " Awaiting approval before being displayed publicly."
 
Last edited:
I'm trying again, without screenshot that shows the attackers ip

This weekend attackers gained access to our pbx using stolen credentials of a user with management console privileges:

- they enabled every kind of international calls
- they disabled all notifications
- they made a lot of calls to "international networks" prefix +882 and several others
- made a bunch of outbound rules
- custom modified an extension
- maybe the downloaded backups (why doesn't the audit show if someone downloads a backup?? tried myself, doesn't show)
 
I'm trying again, without screenshot that shows the attackers ip

This weekend attackers gained access to our pbx using stolen credentials of a user with management console privileges:

- they enabled every kind of international calls
- they disabled all notifications
- they made a lot of calls to "international networks" prefix +882 and several others
- made a bunch of outbound rules
- custom modified an extension
- maybe the downloaded backups (why doesn't the audit show if someone downloads a backup?? tried myself, doesn't show)
Could it be that the reason is not the hack but bad credentials? Since several weeks we can see dozens of login attempts to all of our systems, often it's the same ip that tries to login on the webclient. In the eventlog you can see the passwords they try to use, and to be honest, it's not a real bruteforce attack it's mainly simple password lists like Start1234 and so on. Was the password of the compromised account complex or was it very basic?
 
@mike9055 thank you, Mike, as we too are very nervous and keeping an eye on the logs since all 3CX wants to do is push them to a PWA and not discuss anything else that could possibly be wrong here.
 
oh and i forgot to add: two of our clients that DON'T HAVE a 3CX PBX, but have another cloud pbx we sell were subject to attacks this weekend

Both were recently visited by a collegue running a compromised version of 3CX desktop app on his laptop
 
Could it be that the reason is not the hack but bad credentials? Since several weeks we can see dozens of login attempts to all of our systems, often it's the same ip that tries to login on the webclient. In the eventlog you can see the passwords they try to use, and to be honest, it's not a real bruteforce attack it's mainly simple password lists like Start1234 and so on. Was the password of the compromised account complex or was it very basic?
It's an attack 100%
- Calls were made to international destinations
- settings were modified to do this

i have the audit showing connections form Ukraine, France , UK, same user
 
  • Like
Reactions: daveatgower
It's an attack 100%
- Calls were made to international destinations
- settings were modified to do this

i have the audit showing connections form Ukraine, France , UK, same user
Yes, it's an attack but theese kinds of attacks were always there. Open Port 5001 and the bots try to login, open port 22 facing the internet and some bots try to login via ssh. I don't say that's not an attack but that's nothing special when opening ports to the internet. Also with 3cx theese attempts were always there, but with the new group rights there is the risk that someone can change admin settings.
 
  • Like
Reactions: N_G
Her is what i mean, in 18.6 you could see the login attempts
1680539494546.png
that's no complex attack, that's simple password trying
 
  • Like
Reactions: N_G
It seems you had a colleague who had the compromised 3CX client on their computer and potentially saved credentials in for all three clients. Or are you saying that this colleague went onsite and plugged their laptop into the office and the attackers in that time figured out where the non-3CX cloud PBX was for that customer? It may be related or it could be conjecture. I recommend having said colleague run the Thor scanner linked in the forum for proof that the second stage was activated and then go from there. I would also recommend not storing passwords in the browser and changing any other client passwords that may have been accessed.
 
  • Like
Reactions: accentlogic
Her is what i mean, in 18.6 you could see the login attempts
View attachment 34989
that's no complex attack, that's simple password trying

I understood what you meant, but sadly we have no failed attempts in our log, we have a very long ip blacklist in addition to 3cx one
Of course, you could be right and i could be wrong, but the coincidence is really suspicious, i guess we'll see what happens next weekend
 
It seems you had a colleague who had the compromised 3CX client on their computer and potentially saved credentials in for all three clients. Or are you saying that this colleague went onsite and plugged their laptop into the office and the attackers in that time figured out where the non-3CX cloud PBX was for that customer? It may be related or it could be conjecture. I recommend having said colleague run the Thor scanner linked in the forum for proof that the second stage was activated and then go from there. I would also recommend not storing passwords in the browser and changing any other client passwords that may have been accessed.
What happened was:
- we received a warning form our provider for suspicious traffic
- we checked the numbers, first 2 numbers were related to clients with a frepbx based pbx, both were visited by the same colleague in the last week of march
- the other numbers were from our cloud 3CX which an attacker gained access to a user with management console rights

Plase note that i just want to share what happened and see if anyone else had the same problem after what happened, if our case is isolated that's for the best
 
What happened was:
- we received a warning form our provider for suspicious traffic
- we checked the numbers, first 2 numbers were related to clients with a frepbx based pbx, both were visited by the same colleague in the last week of march
- the other numbers were from our cloud 3CX which an attacker gained access to a user with management console rights

Plase note that i just want to share what happened and see if anyone else had the same problem after what happened, if our case is isolated that's for the best
I've had the same thing happen once in the past (long before the recent attack) where one of our extensions was making a large number of international calls at strange hours. Our carrier flagged it as suspicious activity and temporarily disabled international calling for us. It turned out to be a compromised extension that had a weak auth username and password. It's understandable why 3CX now requires these to be stronger.

As others have said, you're always going to see these random login attempts from unknown IPs. It's just the nature of having a system open to the internet. Folks are going to throw spaghetti against the wall and see what sticks.
 
  • Like
Reactions: Ritter Technologie
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet