North Korea was confirmed responsible for the 3CX supply chain attack
Assessment
No government or intelligence agency has issued a formal public attribution for the 3CX compromise. The word "confirmed" traces to the victim company rather than to an investigating authority: 3CX's chief information security officer, Pierre Jourdan, stated on 11 April 2023 that the company's investigation confirmed North Korean-linked hackers were responsible. The commercial assessments are more qualified than that framing, and they do not agree with one another. Mandiant, which conducted the incident response, tracks the activity as UNC4736 and describes it as a suspected North Korean nexus cluster, assessing only with moderate confidence that it relates to AppleJeus activity. Kaspersky attributes the campaign to Lazarus with medium to high confidence, on the basis that its Gopuram backdoor was found coexisting with AppleJeus malware on victim machines. CrowdStrike names LABYRINTH CHOLLIMA. Mandiant separately characterises the infrastructure overlap with APT43 clusters UNC3782 and UNC4469 as weak. Four designations at four stated confidence levels, none ratified by a government, is not the same thing as confirmation. The assessments are real, reportable, and probably correct — but reporting them as settled fact misrepresents every source they come from.
Where this claim appeared
TechCrunch · 2023-04-11
https://techcrunch.com/2023/04/11/3cx-north-korea-cryptocurrency-hack/What “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
3CX Supply Chain Attack (CVE-2023-29059): The First Cascading Software CompromiseThink this assessment is wrong? Report an error.