logo

Hackers Use Six-Layer Persistence on FreePBX Systems

ID: 0452a53e-57b8-530a-92ee-2a982830b9a9

STIX ID: report--0452a53e-57b8-530a-92ee-2a982830b9a9

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Mayura Kathir

...
...

A financially motivated campaign attributed to INJ3CTOR3 is actively exploiting FreePBX systems using a multi-stage Bash dropper that installs JOMANGY and ZenharR webshells to enable VoIP toll fraud. The operation employs a six-layer persistence architecture, creates numerous backdoor accounts (including root-equivalent), uses identified C2 infrastructure (e.g., 45.234.176.202), and leverages likely vulnerabilities CVE-2025-64328 and CVE-2025-57819; hundreds of systems remain compromised months after patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.