Threat Actors Deploy Multi-Layer Persistence On Compromised FreePBX Servers

A highly sophisticated exploitation campaign is actively targeting FreePBX VoIP infrastructure to facilitate global telecom toll fraud.

Cyble Research & Intelligence Labs (CRIL) attributes this activity with high confidence to INJ3CTOR3, a financially motivated threat actor active since 2019.

The campaign introduces JOMANGY, a previously undocumented PHP webshell family, alongside the established ZenharR toolset.

Every deployed webshell carries live VoIP toll fraud code designed to route calls through a victim’s own SIP trunks at their expense.

An inventory of 3,080 IP addresses hosted on the command-and-control (C2) server highlights the massive scale, with approximately 39% pointing to Alibaba Cloud infrastructure.

This represents automated mass exploitation across multiple regions, including the Asia-Pacific, Latin America, and the Middle East.

FreePBX Hit With Persistence

The primary Bash dropper executes a highly structured host-takeover sequence. It begins by aggressively evicting competing threat actors, actively scrubbing over 50 competitor webshell signatures, and blocking 11 rival C2 IP addresses.

It also systematically deletes artifacts from INJ3CTOR3’s prior January 2026 campaign, cleanly migrating the botnet to new infrastructure in the Netherlands.

Campaign Architecture (Source: cyble)
Campaign Architecture (Source: cyble)

The attacker establishes a massive backdoor presence by dropping 18 accounts across three distinct tiers:

  • Nine UID-0 (root-equivalent) OS accounts use names deliberately chosen to blend into the system.
  • Eight service-account-tier OS accounts share identical MD5-crypt password hashes.
JOMANGY Webshell Operator Panel (Source: cyble)
JOMANGY Webshell Operator Panel (Source: cyble)

What distinguishes this campaign is an intricate, six-layer persistence architecture that allows a single surviving channel to rebuild the infection within minutes, completely. These interconnected self-healing mechanisms include:

  • Recurring cron polling fetches the malicious payload every one to three minutes.
  • Shell profile stagers injected into bash profiles fire on every root login and reboot.
Dashboard Victim overview (shadowserver.org) (Source: cyble)
Dashboard Victim overview (shadowserver.org) (Source: cyble)

While the exact initial entry vector remains unconfirmed, forensic artifacts point to two highly probable vulnerabilities.

The campaign consistently scrubs Apache logs for specific application strings and explicitly targets proof-of-concept files linked to a known WatchTowr Labs exploit. Researchers assess the following CVEs as the primary candidates:

  • CVE-2025-64328: A post-authentication command-injection vulnerability in the FreePBX filestore module.
  • CVE-2025-57819: A pre-authentication SQL injection flaw in the FreePBX Endpoint module operating via the system scheduler.

According to Cyble research, the JOMANGY webshell uses double-layer obfuscation to evade static detection heuristics.

An outer base64 layer encodes a PHP string that applies the ROT13 cipher to a second encoded layer before passing the resulting execution to the server.

The threat actor actively rotates these payload contents, resulting in near-zero detection rates across major antivirus engines during initial deployment.

Attribution to INJ3CTOR3 is corroborated by overlapping technical indicators observed by Fortinet, Palo Alto Unit 42, Check Point Research, and the SANS Internet Storm Center.

Shared infrastructure, identical eviction targets, recurring file paths, and continuous C2 URL frameworks clearly link this operation to the group’s long-running VoIP fraud activities.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories