Related Threat Clusters
-
INJ3CTOR3 Targets FreePBX Systems with JOMANGY Webshell and VoIP Toll Fraud
A cyber campaign attributed to the threat actor INJ3CTOR3 is targeting FreePBX systems, deploying a new PHP webshell named JOMANGY. This operation utilizes a six-layer persistence mechanism to maintain control over…
5 articles · Updated May 22, 2026 -
Moscow Man Accused of Extorting Conti Ransomware Gang as FSB Impersonator
Ruslan Satuchin, a Moscow resident, has been accused of attempting to extort the Conti ransomware group by impersonating an officer of Russia's Federal Security Service (FSB). Local media reports indicate that he…
4 articles · Updated February 26, 2026 -
Approximately 900 Sangoma FreePBX Systems Compromised via CVE-2025-64328
Approximately 900 Sangoma FreePBX systems are compromised due to CVE-2025-64328, a command injection vulnerability. This bug was patched in version 17.0.3, but many systems remain unpatched and vulnerable to…
1 article · Updated February 28, 2026 -
900 Sangoma FreePBX Instances Compromised by CVE-2025-64328 Exploitation
Attackers exploited CVE-2025-64328, a command injection vulnerability, affecting 900 Sangoma FreePBX systems. The exploitation resulted in the installation of web shells, with hundreds of instances remaining compromised…
5 articles · Updated March 1, 2026 -
Attackers Exploit FreePBX Vulnerability to Deploy EncystPHP Webshell
Hackers are exploiting a critical vulnerability in FreePBX, specifically CVE-2025-64328, to deploy a persistent webshell named EncystPHP. This attack, attributed to the group INJ3CTOR3, allows complete administrative…
2 articles · Updated January 29, 2026
Recent Intelligence Reports
- Hackers Use Six-Layer Persistence on FreePBX Systems — Gbhackers · May 22, 2026
- INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks — Thecyberexpress · May 22, 2026
- Ongoing Cyberattack Exploits Sangoma FreePBX CVE-2025-64328: Over 900 Instances ... — Rescana · March 1, 2026
- CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances — Securityaffairs · March 1, 2026
- WARNING: ~900 Sangoma FreePBX systems remain compromised via CVE-2025-64328, a ... — X · February 27, 2026
- Risky Bulletin: Russian man investigated for extorting Conti ransomware group — News.Risky.Biz · February 27, 2026
- Hackers Exploiting FreePBX Vulnerability to Deploy Webshell and Gain Control of Systems — Cybersecuritynews · January 29, 2026