Frequency
3
occurrences
First Seen
March 1, 2026
Last Seen
May 22, 2026
Related Threat Clusters
-
INJ3CTOR3 Targets FreePBX Systems with JOMANGY Webshell and VoIP Toll Fraud
A cyber campaign attributed to the threat actor INJ3CTOR3 is targeting FreePBX systems, deploying a new PHP webshell named JOMANGY. This operation utilizes a six-layer persistence mechanism to maintain control over…
5 articles · Updated May 22, 2026 -
900 Sangoma FreePBX Instances Compromised by CVE-2025-64328 Exploitation
Attackers exploited CVE-2025-64328, a command injection vulnerability, affecting 900 Sangoma FreePBX systems. The exploitation resulted in the installation of web shells, with hundreds of instances remaining compromised…
5 articles · Updated March 1, 2026
Recent Intelligence Reports
- Hackers Use Six-Layer Persistence on FreePBX Systems — Gbhackers · May 22, 2026
- Hackers Use Six — Gbhackers · May 22, 2026
- Ongoing Cyberattack Exploits Sangoma FreePBX CVE-2025-64328: Over 900 Instances ... — Rescana · March 1, 2026