logo

INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks

ID: eaa50df2-6847-594e-859f-cdaa9794b6dc

STIX ID: report--eaa50df2-6847-594e-859f-cdaa9794b6dc

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-05-22

Date Updated: 2026-07-20

Author: Ashish Khaitan

...
...

Researchers at Cyble reported a large-scale, persistent campaign attributed to INJ3CTOR3 that infects FreePBX systems with a new PHP webshell family (JOMANGY) and the ZenharR toolkit to establish resilient backdoors, create UID-0 accounts, and abuse SIP trunks for VoIP toll fraud; the multi-stage Bash droppers and self-healing persistence (cron jobs, immutable files, watchdogs, webshell replicas) enable rapid recovery after remediation and the operation appears to target thousands of systems using likely post-auth and pre-auth FreePBX vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.