JOMANGY: INJ3CTOR3’s Self-Healing FreePBX Toll Fraud Campaign
ID: 7c44aa97-3e91-5251-b92b-6456da9f721d
STIX ID: report--7c44aa97-3e91-5251-b92b-6456da9f721d
Feed Name: Cyble Blog
Cyble Research & Intelligence Labs documents an active INJ3CTOR3 FreePBX campaign that deploys a multi-stage Bash dropper and a newly described PHP webshell family (JOMANGY) alongside ZenharR to enable VoIP toll fraud; the implants use double-layer obfuscation, carry a consistent watermark, establish six mutually reinforcing persistence channels (cron polling, shell-profile stagers, immutable crontab backups, process watchdogs, chattr-protected webshell copies, and a PHP executor), plant 18 backdoor accounts (including nine UID-0), and are assessed to have been distributed across a C2-hosted inventory of 3,080 addresses with active exploitation and significant remediation challenges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
