logo

Silent Intruder: “EncystPHP” Web Shell Burrows into FreePBX Systems

ID: eaed2c92-e9c9-522d-ae51-4cb48f8674ef

STIX ID: report--eaed2c92-e9c9-522d-ae51-4cb48f8674ef

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-02

Date Updated: 2026-04-23

Author: Ddos

...
...

FortiGuard researchers uncovered "EncystPHP", a PHP web shell deployed against FreePBX via a post-authentication command-injection vulnerability (CVE-2025-64328). Linked to the INJ3CTOR3 group, the campaign grants remote command execution, establishes persistence through cron jobs (downloading from 45.234.176.202 and using a license.php persistence script), and attempts log cleanup; administrators are advised to patch and audit compromised PBX systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.