logo

Threat Actors Deploy Multi-Layer Persistence On Compromised FreePBX Servers

ID: 017819cc-c46f-5253-b3b2-157b0e3b4c65

STIX ID: report--017819cc-c46f-5253-b3b2-157b0e3b4c65

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Varshini

...
...

An active, large-scale campaign attributed to INJ3CTOR3 is exploiting FreePBX VoIP systems worldwide to install a novel JOMANGY PHP webshell and ZenharR toolset for telecom toll fraud; the operation includes multi-layer persistence, deployment of root-equivalent accounts, eviction of competing actors, and mass C2 infrastructure (≈3,080 IPs, ~39% on Alibaba Cloud), with likely use of CVE-2025-64328 and CVE-2025-57819 for initial access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.