{
  "type": "bundle",
  "id": "bundle--36a73143-560e-5b4e-81f9-9462d30276fe",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--0dd1edd0-7720-533c-828c-b5ce0b74bf8a",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:0386a533-c8e2-5120-b15a-60a8462c5b58",
      "name": "3CX",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--e6eef83a-2571-5b34-86b4-18128f1860f4",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:2308eecd-1a72-5157-8692-1402f0547555",
      "name": "3CX supply-chain compromise"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--eb872a93-546a-5be0-8f32-2bd134ae4be4",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:15fd81ce-9a11-5d46-beeb-91dc2d24c814",
      "name": "3CX supply-chain compromise"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--f01da497-f5ef-5418-83b0-8427ae87bb8f",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:b5d3b3ed-56c1-5d6a-a61f-bc12d68e8044",
      "relationship_type": "affected-organization",
      "source_ref": "incident--e6eef83a-2571-5b34-86b4-18128f1860f4",
      "target_ref": "identity--0dd1edd0-7720-533c-828c-b5ce0b74bf8a",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Google Cloud Mandiant",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise",
          "external_id": "cit:4f118636-70d5-595f-9067-1dbac7549499",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:bab98f247961c9ae9b6b35823df6b119d7771edb21553bd5e7cdf2c07e960d19"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--3a4feedf-2a46-5ebc-89e7-c1ea772c3a66",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:20b447ca-c000-53b9-89c4-a7aac1845e58",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Google Cloud Mandiant",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise",
          "external_id": "cit:45a756b4-f5ba-54fe-97cb-3275d989f68e",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9e35eaa94c636422c587b78e0ef50f072d1e6ca1d4e9a8761ae39f52988a7bd9"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "date",
        "value": "2023-04-20"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--cb627b50-0b9f-5fba-8174-cfd3b477c556",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:b31d8603-e6a1-55f9-9431-5abc0f952894",
      "confidence": 87,
      "external_references": [
        {
          "source_name": "Google Cloud Mandiant",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise",
          "external_id": "cit:35e2836f-6f27-5c54-a96b-7987f4744ec3",
          "description": "Mandiant Consulting’s investigation of the 3CX supply chain compromise has uncovered the initial intrusion vector: a malware-laced software package distributed via an earlier software supply chain compromise that began with a tampered installer for X_TRADER, a software package provided by Trading Technologies (Figure 1).",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9e35eaa94c636422c587b78e0ef50f072d1e6ca1d4e9a8761ae39f52988a7bd9"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Notable \"double supply chain\" attack — 3CX itself was compromised via an earlier trojanized trading app."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--d39100d5-e1ce-5bfc-8077-39cbf277a9f3",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:b7ca7980-f4cb-55de-b45e-6fbeaa208611",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Google Cloud Mandiant",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise",
          "external_id": "cit:bea9363b-e9ca-54b8-9c44-f1742c868da9",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:bab98f247961c9ae9b6b35823df6b119d7771edb21553bd5e7cdf2c07e960d19"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the 3cx supply-chain compromise involving 3CX."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--d9dbbe60-7957-5945-85f5-26155b434ed6",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:98d702cc-bb1a-59d9-a447-ea65aef53d97",
      "confidence": 88,
      "external_references": [
        {
          "source_name": "Google Cloud Mandiant",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/3cx-software-supply-chain-compromise",
          "external_id": "cit:846be2a7-387e-53c4-aa87-adbfc9ebec02",
          "description": "Mandiant assesses with moderate confidence that UNC4736 is related to financially motivated North Korean “AppleJeus” activity as reported by CISA.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:9e35eaa94c636422c587b78e0ef50f072d1e6ca1d4e9a8761ae39f52988a7bd9"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "North Korean-linked (Lazarus/UNC4736); trojanized desktop app."
      }
    },
    {
      "type": "x-ally-event",
      "spec_version": "2.1",
      "id": "x-ally-event--4ab62cb5-cec0-5185-82a4-a855ab6b2b5a",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "evt:c3a70c1d-7008-531b-b22e-8e816d889143",
      "name": "Documented public update"
    }
  ]
}
