INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks
ID: eaa50df2-6847-594e-859f-cdaa9794b6dc
STIX ID: report--eaa50df2-6847-594e-859f-cdaa9794b6dc
Feed Name: The Cyber Express
Researchers at Cyble reported a large-scale, persistent campaign attributed to INJ3CTOR3 that infects FreePBX systems with a new PHP webshell family (JOMANGY) and the ZenharR toolkit to establish resilient backdoors, create UID-0 accounts, and abuse SIP trunks for VoIP toll fraud; the multi-stage Bash droppers and self-healing persistence (cron jobs, immutable files, watchdogs, webshell replicas) enable rapid recovery after remediation and the operation appears to target thousands of systems using likely post-auth and pre-auth FreePBX vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
