logo

Unveiling the Weaponized Web Shell EncystPHP

ID: 574b02a1-ac23-541a-bb4d-e7bb4ba1dd7e

STIX ID: report--574b02a1-ac23-541a-bb4d-e7bb4ba1dd7e

Feed Name: Fortinet Blog

Threat Score
80/100

Date Published: 2026-01-28

Date Updated: 2026-04-27

...
...

FortiGuard Labs discovered an active campaign leveraging CVE-2025-64328 in FreePBX Endpoint Manager to deliver a Base64-encoded PHP web shell named "EncystPHP." The dropper modifies file permissions, harvests credentials, deletes competing web shells, creates a root-level backdoor account (newfpbx), injects an SSH key, establishes multiple cron-based persistence mechanisms, and deploys the web shell to numerous FreePBX/Elastix paths to enable remote command execution and abuse of telephony resources; the report includes IOCs, MITRE ATT&CK mappings, and Fortinet detections/mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.