logo

Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems

ID: f0f8fe9d-75f5-5c60-a808-b6779424fae5

STIX ID: report--f0f8fe9d-75f5-5c60-a808-b6779424fae5

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-22

Date Updated: 2026-05-23

Author: Tushar Subhra Dutta

...
...

The report describes an active INJ3CTOR3 campaign exploiting FreePBX vulnerabilities to deploy the JOMANGY PHP webshell that uses six interdependent persistence mechanisms and multiple backdoor accounts to maintain long-term access and route toll-fraud calls; researchers tracked thousands of targets, hundreds of infected hosts, and published detailed IoCs and remediation guidance advising full rebuilds of compromised systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.