logo

Massive FreePBX Exploitation Campaign Deploys JOMANGY Webshell

ID: 93f29e3f-3fe4-5fcf-95e9-cc416a9c9160

STIX ID: report--93f29e3f-3fe4-5fcf-95e9-cc416a9c9160

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Ddos

...
...

**Cyble Research & Intelligence Labs uncovered an active INJ3CTOR3 campaign exploiting FreePBX vulnerabilities (CVE-2025-64328, CVE-2025-57819) to deploy a newly documented PHP webshell dubbed JOMANGY that performs VoIP toll fraud, implements double-layer obfuscation, enforces competitor eviction, and maintains access via six independent persistence channels (cron, profile insertion, watchdogs, multiple filesystem locations and immutable attributes), making full eradication difficult and often requiring complete system rebuilds.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.