# INJ3CTOR3

> As of 2026-05-30, INJ3CTOR3 is a Palestinian Territories (Gaza)-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware, vulnerability. Also known as INJ3CTOR3 Crew, JOMANGY operators, INJ3CTOR3 Group, VoIP Toll Fraud Operators. ATT&CK coverage spans 43 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1053 (Scheduled Task/Job).

- **Nation:** Palestinian Territories (Gaza)
- **Tracked threats:** 2
- **Categories:** MALWARE, VULNERABILITY
- **Also known as:** INJ3CTOR3 Crew, JOMANGY operators, INJ3CTOR3 Group, VoIP Toll Fraud Operators
- **As of:** 2026-05-30

## ATT&CK techniques observed

43 techniques observed across 2 of 2 tracked threats. Tactics: Persistence (6), Stealth (formerly Defense Evasion) (6), Command and Control (5), Discovery (5), Collection (3), Credential Access (3).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 2 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 2 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 2 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 2 tracked threats
- [T1496](https://intel.threadlinqs.com/technique/T1496) Resource Hijacking — Impact — observed in 2 of 2 tracked threats
- [T1505](https://intel.threadlinqs.com/technique/T1505) Server Software Component — Persistence — observed in 2 of 2 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 2 of 2 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 2 of 2 tracked threats

## Tracked threats

- [JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign (CVE-2025-64328)](https://intel.threadlinqs.com/threat/TL-2026-0550) — HIGH
- [Sangoma FreePBX Authentication Bypass & Command Injection - CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-0058) — CRITICAL

## Related CVEs

2 CVEs referenced by tracked INJ3CTOR3 activity.

- [CVE-2025-64328](https://intel.threadlinqs.com/cve/CVE-2025-64328)
- [CVE-2019-19006](https://intel.threadlinqs.com/cve/CVE-2019-19006)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/INJ3CTOR3
