The 3CX attackers were linked to the North Korean group APT43
Assessment
Mandiant identified shared IP infrastructure between UNC4736, the cluster responsible for the 3CX and X_TRADER compromises, and two clusters associated with APT43 — UNC3782 and UNC4469 — across three addresses: 89.45.67.160, 172.93.201.88 and 185.38.151.11. Mandiant characterised that overlap as weak, in its own words, and the published DNS resolutions show why. The domains sharing each address resolved weeks or months apart: 172.93.201.88 was used by an UNC3782 domain in November 2021 and by an UNC4736 domain in April 2022; 185.38.151.11 by UNC4736 in January 2023 and by UNC4469 in March 2023. Shared hosting among North Korean clusters is common and does not establish that the same operators were involved. The link is reported downstream without the qualifier that Mandiant attached to it. That is the flattening this rating records: the observation is real and worth reporting, but Mandiant's assessment of its strength is part of the finding, not an optional footnote to it.
Where this claim appeared
BleepingComputer · 2023-04-20
https://www.bleepingcomputer.com/news/security/3cx-hack-caused-by-trading-software-supply-chain-attack/What “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software CompromiseThink this assessment is wrong? Report an error.