Skip to content
Hackers Use Six-Layer Persistence on FreePBX Systems

Hackers Use Six-Layer Persistence on FreePBX Systems

Gbhackers May 22, 2026

Hackers are actively exploiting FreePBX systems using a highly resilient six-layer persistence mechanism. The campaign has been attributed with high confidence to the threat actor INJ3CTOR3, known for targeting VoIP infrastructure for financial gain since 2019.

The operation deploys a multi-stage Bash dropper that installs a previously undocumented PHP webshell family named JOMANGY, alongside the known ZenharR webshell.

Both tools are designed to enable VoIP toll fraud by abusing compromised systems to route unauthorized calls through victims’ SIP trunks, ultimately charging the victim for fraudulent activity.

Attackers can execute commands such as initiating calls directly through Asterisk, allowing them to monetize access without deploying ransomware or stealing data. This method reduces operational complexity while ensuring steady financial returns.

One of the most notable aspects of this campaign is its advanced persistence architecture. The attackers implement six independent persistence mechanisms that reinforce each other.

Cyble Research & Intelligence Labs (CRIL) has identified an active FreePBX exploitation campaign , with high confidence tied to INJ3CTOR3.

These include cron-based command-and-control polling, shell profile modifications that trigger on login or reboot, immutable crontab backups protected using Linux file attributes, a process watchdog that restarts malicious components, multiple protected webshell copies, and a PHP-based executor that can reinstall the entire infection chain.

This layered design ensures that even if defenders remove several components, any remaining mechanism can fully restore the infection within minutes.

As a result, partial remediation efforts are largely ineffective, forcing organizations to consider complete system rebuilds to eliminate the threat.

Palo Alto Unit 42 followed with a ZenharR-deploying generation targeting CVE-2021-45461 in 2022. Fortinet then covered the January 2026 encystPHP iteration operating from C2 45[.]234[.]176[.]202.

The infection chain also introduces 18 backdoor accounts across the compromised system. These accounts are strategically distributed across privilege levels, including nine with root-equivalent access. The attackers use names such as “asterisk,” “freepbxuser,” and “spamfilter” to blend into legitimate service accounts, making detection more difficult.

Researchers identified a command-and-control server hosting a list of 3,080 IP addresses, believed to be targets identified through automated scanning.

Approximately 39 percent of these systems are hosted on Alibaba Cloud infrastructure , indicating a strong focus on the Asia-Pacific region. However, the campaign’s reach extends globally, affecting organizations across multiple sectors.

Although the exact initial access vector was not confirmed, evidence points to two likely vulnerabilities: CVE-2025-64328, a command injection flaw in the FreePBX filestore module, and CVE-2025-57819, a pre-authentication SQL injection in the Endpoint module. The latter is considered particularly likely due to its suitability for large-scale automated exploitation.

The malware also includes routines to remove competing webshells and block rival command-and-control servers, effectively monopolizing infected systems. In some cases, it even removes artifacts from earlier campaigns linked to the same actor, suggesting a deliberate migration of infrastructure.

The operator rotates k.php actively. The artifact collected (100259af, ~45KB) and the VT URL last-fetch variant (49abb105, retrieved 2026-04-29) are distinct.

Despite patches being available for the suspected vulnerabilities, remediation remains challenging. Data from Shadowserver indicates that hundreds of FreePBX systems remain compromised months after disclosure, highlighting the difficulty of eradicating deeply persistent threats.

This campaign underscores the growing risk of VoIP-focused attacks within the broader telecom fraud landscape, which continues to generate billions in global losses.

With FreePBX systems widely exposed to the internet and often poorly secured, they remain a prime target for financially motivated attackers like INJ3CTOR3.

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hackers are increasingly abusing Middle East telecommunications networks and hosting providers to operate large-scale command-and-control…

Google’s recent release of proof-of-concept (PoC) exploit code for a still-unpatched Chromium vulnerability has sparked…

The scale of phishing activity targeting the 2026 FIFA World Cup has expanded dramatically, with…

Russian state- and aligned threat groups are increasingly combining Remote Desktop Protocol (RDP), Virtual Private…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked…

Hackers compromised the popular art-template npm package to inject a stealthy backdoor that redirected users’…