Silent Intruder: “EncystPHP” Web Shell Burrows into FreePBX Systems
ID: eaed2c92-e9c9-522d-ae51-4cb48f8674ef
STIX ID: report--eaed2c92-e9c9-522d-ae51-4cb48f8674ef
Feed Name: securityonline.info
Threat Score
FortiGuard researchers uncovered "EncystPHP", a PHP web shell deployed against FreePBX via a post-authentication command-injection vulnerability (CVE-2025-64328). Linked to the INJ3CTOR3 group, the campaign grants remote command execution, establishes persistence through cron jobs (downloading from 45.234.176.202 and using a license.php persistence script), and attempts log cleanup; administrators are advised to patch and audit compromised PBX systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
