Threadlinqs IntelligenceStart free

Threat actorPalestinian Territories (Gaza)Tracked since 2026-02

INJ3CTOR3

Also known as:INJ3CTOR3 CrewJOMANGY operatorsINJ3CTOR3 GroupVoIP Toll Fraud Operators

As of 2026-05-30, INJ3CTOR3 is a Palestinian Territories (Gaza)-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware, vulnerability. Also known as INJ3CTOR3 Crew, JOMANGY operators, INJ3CTOR3 Group, VoIP Toll Fraud Operators. ATT&CK coverage spans 43 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1053 (Scheduled Task/Job).

Tracked threats
21 critical · 1 high
First seen
2026-02-03
Last seen
2026-05-21
ATT&CK techniques
43across 2 of 2 threats
Related CVEs
2Referenced by its activity
Attribution
Palestinian Territories (Gaza)Nation or origin
Nation: Palestinian Territories (Gaza) · 2 tracked threat(s) · Categories: MALWARE, VULNERABILITY

Activity timeline

INJ3CTOR3 appears in 2 tracked threats between and ; the busiest month was 2026-02 with 1 report.

ATT&CK techniques observed

43 techniques observed across 2 of 2 tracked threats · Persistence (6), Stealth (formerly Defense Evasion) (6), Command and Control (5), Discovery (5), Collection (3), Credential Access (3)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1053 Scheduled Task/Job — Persistenceobserved in 2 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 2 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 2 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 2 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 2 tracked threats
  • T1496 Resource Hijacking — Impactobserved in 2 of 2 tracked threats
  • T1505 Server Software Component — Persistenceobserved in 2 of 2 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 2 of 2 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 2 of 2 tracked threats

Tracked threats

Related CVEs

2 CVEs referenced by tracked INJ3CTOR3 activity