Threat reportMalwareTL-2026-0550
JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign (CVE-2025-64328)
JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign (TL-2026-0550), also tracked as JOMANGY Campaign, is a high-severity malware campaign scored CVSS 8.6, first published 2026-05-21. It is attributed to INJ3CTOR3 (Palestine) with medium confidence, affects Sangoma FreePBX Endpoint Manager (filestore module), references 1 CVE (CVE-2025-64328), maps to 20 MITRE ATT&CK techniques (T1027, T1036, T1053), and is covered by 9 detection rules and 21 indicators of compromise.
- CVSS
- 8.6/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 20MITRE ATT&CK
- Actors
- 1INJ3CTOR3
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-0550
- Threat ID
- TL-2026-0550
- Also known as
- JOMANGY Campaign, EncystPHP FreePBX Campaign, INJ3CTOR3 2025-2026 Wave
- Severity
- HIGH
- CVSS
- 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- INJ3CTOR3
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Palestine
- Motivation
- FINANCIAL
- Target sectors
- telecommunications, managed service providers, small and medium business, hospitality, healthcare, education, government
- Target regions
- United States, Brazil, Canada, Germany, France, United Kingdom, Italy, Spain, Mexico, Australia
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign
Malware and tooling: EncystPHP, EncystPHP, EncystPHP modular.php C2
How JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign works
INJ3CTOR3 — a Gaza-based financially motivated actor active since 2020 — has compromised 900+ Sangoma FreePBX instances since early December 2025 by exploiting CVE-2025-64328, a post-authentication OS command injection in the FreePBX Endpoint Manager filestore module's SSH connection-test function. Attackers deploy the EncystPHP web shell masquerading as ajax.php across multiple /var/www/html/ subdirectories and install a crontab-driven k.php dropper that re-fetches the shell every minute, creating self-healing persistence used to drive premium-rate VoIP toll-fraud calls. Patched in FreePBX 17.0.3 and added to the CISA KEV catalog on 2026-02-03; victims are concentrated in the United States (401), Brazil, Canada, Germany, and France.
## Overview
TL-2026-0550 tracks an ongoing financially motivated intrusion campaign — internally dubbed JOMANGY by some responders — in which the long-running INJ3CTOR3 crew is exploiting CVE-2025-64328 to mass-compromise internet-facing Sangoma FreePBX PBX servers. As of late February 2026, multiple vendors (The Hacker News, SecPod, Fortinet FortiGuard Labs) corroborate that more than 900 live FreePBX instances have been backdoored since early December 2025. Sangoma published a patch in FreePBX 17.0.3 on 2025-11-07, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2026-02-03 with a federal remediation deadline of 2026-02-24, but a large unpatched population remains exposed.
## Vulnerability — CVE-2025-64328
CVE-2025-64328 (CWE-78, OS Command Injection) lives in the filestore module that ships with the FreePBX Endpoint Manager (commercial module, very widely installed). Specifically, the SSH driver's `testconnection.php` calls `check_ssh_connect()` and concatenates attacker-controllable connection parameters into a shell command without adequate sanitization. Because the vulnerable endpoint is reachable from the Administrative interface, an authenticated user with access to Endpoint Manager — including any account whose session can be forged or stolen from a previously breached host — can invoke the SSH connection-test feature with a crafted host/port/key payload and obtain command execution as the `asterisk` user. CVSS 4.0 scores the bug 8.6 HIGH (CVSS 3.1 base 7.2) and the vendor advisory is GHSA-vm9p-46mv-5xvw. Affected range: FreePBX Endpoint Manager filestore module versions 17.0.2.36 up to but not including 17.0.3. The fix is in 17.0.3.
## Exploit Chain
1. Initial Access — INJ3CTOR3 scans for internet-exposed FreePBX Administrative interfaces and either reuses harvested credentials, leverages default/weak admin accounts left exposed by integrators, or chains through unpatched authentication weaknesses to obtain a valid session cookie. Many victims are managed-service-provider hosted PBX systems with predictable admin URLs. 2. Vulnerability Trigger — The attacker browses to the Endpoint Manager and submits a POST request to the filestore SSH test endpoint with shell metacharacters embedded in the host or key arguments. The vulnerable `check_ssh_connect()` builds a shell command from these fields and executes it, yielding RCE as `asterisk`. 3. Payload Delivery — The initial command writes a small PHP dropper (k.php) to disk, typically into `/var/www/html/admin/modules/`, and then fetches the EncystPHP web shell payload from operator infrastructure. EncystPHP is dropped under multiple legitimate-looking names — most commonly `ajax.php` — into several FreePBX phone-module web roots: `/var/www/html/digium_phones/`, `/var/www/html/rest_phones/`, `/var/www/html/phones/`, and `/var/www/html/freepbxphones/`. The multiple copies are deliberate redundancy. 4. Persistence (Self-Healing) — A crontab entry is added for the asterisk or root user that runs every minute and `wget`/`curl`s k.php (or directly the EncystPHP body) from operator infrastructure, rewriting the web shell files if defenders delete them. A small `/var/www/html/.clean.sh` cleanup script removes telltale logs. This crontab + remote redeploy pattern is the campaign's signature 'self-healing' behaviour and is the reason most observed victims keep re-infecting after naïve cleanups. 5. Command and Control / Operator Interaction — Operators interact with EncystPHP via HTTP POST requests to `modular.php` (and to the ajax.php-named copies) carrying base64-encoded, sometimes XOR-obfuscated, command payloads. The shell supports file upload/download, arbitrary PHP/shell execution, and direct invocation of Asterisk Manager Interface (AMI) commands and dialplan originations. 6. Monetization (Impact) — The actor uses Asterisk dialplan abuse and AMI-originated calls to place outbound calls to attacker-controlled premium-rate / international-premium numbers, frequently routed via dialled extension 9998. Outbound trunks belonging to the victim are billed for these calls; INJ3CTOR3 collects revenue-share from the premium-rate carrier. This is classic International Revenue Share Fraud (IRSF) / toll fraud, a tradecraft that Check Point Research first documented for INJ3CTOR3 in November 2020 when the actor was abusing SIP/Asterisk via earlier remote_call.php and other web-shell families.
## Threat Actor — INJ3CTOR3
INJ3CTOR3 is a Gaza-based, Arabic-speaking, financially motivated threat actor first publicly profiled by Check Point Research in November 2020 ("INJ3CTOR3 Operation - Leveraging Asterisk Servers for Monetization"). The group sells access to compromised SIP/VoIP servers and operates IRSF/toll-fraud monetization infrastructure. Membership has been linked to underground Arabic-language hacking forums and Telegram channels selling 'SIP servers,' 'asterisk shells,' and 'dialer panels.' Attribution to this same crew for the 2025-2026 FreePBX wave is supported by: (a) reuse of the EncystPHP web-shell code base previously seen in 2021-2024 incidents against Asterisk/FreePBX, (b) reuse of the modular.php / k.php naming convention, (c) operator infrastructure overlap, and (d) consistent IRSF monetization pattern.
## Affected Products and Versions
FreePBX (open-source PBX distribution maintained by Sangoma) with the Endpoint Manager commercial module installed. Vulnerable filestore module versions: 17.0.2.36 through pre-17.0.3. Fixed in Endpoint Manager filestore 17.0.3 (released as part of FreePBX 17 updates on 2025-11-07). Versions of FreePBX 16.x and earlier are not impacted by this specific CVE but have historically been targeted by INJ3CTOR3 via other vulnerabilities. Note: even after applying the patch, victims must hunt for residual EncystPHP files and crontab entries, because the self-healing persistence survives a simple module upgrade.
## Remediation Priority
Critical and time-sensitive for any internet-facing FreePBX instance. Patch to 17.0.3+, audit for IOC paths, scrub crontabs, rotate Endpoint Manager admin credentials, and restrict the Administrative interface to a management VLAN or VPN. Where possible, place SIP trunks behind a Session Border Controller with outbound destination allow-lists and per-extension rate limiting to cap toll-fraud blast radius even if compromise is missed.
MITRE ATT&CK techniques used in TL-2026-0550
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
Persistence
T1053 Scheduled Task/Job; T1505 Server Software Component
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1132 Data Encoding
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Impact
T1496 Resource Hijacking; T1657 Financial Theft
Credential Access
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Reconnaissance
Affected products and versions in JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign
- Sangoma — FreePBX Endpoint Manager (filestore module)
Vulnerable versions: 17.0.2.36 through pre-17.0.3
Fixed in: 17.0.3 - Sangoma — FreePBX
Vulnerable versions: FreePBX 17 deployments with Endpoint Manager filestore 17.0.2.36 - 17.0.2.x
Fixed in: FreePBX 17 with Endpoint Manager filestore 17.0.3+
Remediation for JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign
Patches
- FreePBX Endpoint Manager filestore module 17.0.3 (vendor advisory GHSA-vm9p-46mv-5xvw, released 2025-11-07)
Immediate actions
- Patch FreePBX Endpoint Manager filestore module to version 17.0.3 or later on every internet-facing PBX
- Remove EncystPHP web shell artifacts from /var/www/html/digium_phones/, /var/www/html/rest_phones/, /var/www/html/phones/, and /var/www/html/freepbxphones/ — specifically any rogue ajax.php and modular.php
- Delete /var/www/html/.clean.sh and any k.php dropper from /var/www/html/ and /var/www/html/admin/modules/
- Audit and clean crontab entries for the asterisk and root users that fetch k.php or other remote PHP every minute
- Block outbound calls to dialled extension 9998 and to known premium-rate / high-cost international destinations not used for business
- Rotate all FreePBX Administrative interface credentials (admin, integrator, MSP service accounts)
- Restrict the Administrative interface to a management VLAN or IPsec/WireGuard VPN; never expose port 80/443 of FreePBX directly to the internet
- Review SIP trunk CDRs (Call Detail Records) for the last 120 days for premium-rate / international anomaly traffic and dispute fraudulent billing with the carrier
Workarounds
- If the patch cannot be applied immediately, disable the Endpoint Manager filestore SSH driver feature and block administrative access to /admin/config.php?display=filestore at the reverse proxy
- Place the FreePBX Administrative interface behind HTTP basic-auth or mTLS at the upstream proxy until patched
Longer-term hardening
- Deploy a Session Border Controller (SBC) in front of SIP trunks with outbound destination allow-lists and per-extension call-rate limiting
- Enable Asterisk AMI access control: bind AMI to 127.0.0.1, require strong per-user secrets, and log all AMI logins
- Deploy file-integrity monitoring (AIDE, Wazuh FIM, Tripwire) on /var/www/html/ to catch web-shell drops in real time
- Forward FreePBX, Apache, Asterisk full call, and auth logs to a SIEM with detections for the IOCs in this report
- Subscribe to Sangoma FreePBX security advisories and apply security module updates within 7 days of release
CVEs associated with JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign
Weaknesses (CWE) in JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign
Timeline of JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign
- Check Point Research publishes 'INJ3CTOR3 Operation - Leveraging Asterisk Servers for Monetization,' the first detailed public profile of the Gaza-based INJ3CTOR3 crew exploiting SIP/Asterisk servers for IRSF / premium-rate toll fraud.
- Sangoma publishes advisory GHSA-vm9p-46mv-5xvw and releases FreePBX Endpoint Manager filestore module 17.0.3, fixing CVE-2025-64328 — a post-authentication OS command injection in the SSH driver's check_ssh_connect() function. NVD publishes the CVE the same day.
- First wave of in-the-wild exploitation of CVE-2025-64328 observed against internet-facing FreePBX 17 instances. EncystPHP web shells and k.php droppers begin appearing on Fortinet, SecPod, and Sangoma telemetry.
- CISA adds CVE-2025-64328 to the Known Exploited Vulnerabilities catalog as 'Sangoma FreePBX OS Command Injection Vulnerability' with a federal civilian agency remediation deadline of 2026-02-24.
- CISA BOD 22-01 remediation deadline for federal civilian agencies to patch CVE-2025-64328.
- Fortinet FortiGuard Labs publishes 'Unveiling the Weaponized Web Shell EncystPHP,' attributing the FreePBX campaign to INJ3CTOR3 and detailing the EncystPHP shell, modular.php C2 endpoint, and self-healing crontab persistence.
- The Hacker News reports 900+ Sangoma FreePBX instances compromised — 401 in the United States, with significant clusters in Brazil, Canada, Germany, and France.
- SecPod publishes a follow-up analysis confirming INJ3CTOR3 attribution, the EncystPHP deployment pattern across /digium_phones/, /rest_phones/, /phones/, and /freepbxphones/ web roots, and ongoing toll-fraud monetization via outbound calls to extension 9998.
- Threadlinqs Intelligence publishes TL-2026-0550 with full MITRE mapping, exploit-chain analysis, IOC set, and detection coverage for SOC ingestion.
- As of 2026-05-29, this is still ACTIVE: CVE-2025-64328 remains in CISA KEV under active exploitation, with ~700+ of 900+ FreePBX hosts still web-shelled. INJ3CTOR3 is escalating, not contained — May 2026 reporting shows a new JOMANGY six-layer-persistence wave and a Brazil-to-Dutch C2 migration, with no takedown or arrests.
Sources cited for JOMANGY: INJ3CTOR3 Self-Healing FreePBX Toll Fraud Campaign
- 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
- Ongoing Web Shell Attacks Hit 900+ FreePBX Systems: INJ3CTOR3 Behind EncystPHP Deployment
- Unveiling the Weaponized Web Shell EncystPHP
- GHSA-vm9p-46mv-5xvw - FreePBX Endpoint Manager Command Injection
- FreePBX testconnection.php (vulnerable source)
- CISA Known Exploited Vulnerabilities Catalog - CVE-2025-64328
- NVD - CVE-2025-64328
- INJ3CTOR3 Operation - Leveraging Asterisk Servers for Monetization
- Malpedia - INJ3CTOR3 Threat Actor Profile
- FreePBX Security Fixes Announcement
Detection coverage for TL-2026-0550
As of 2026-05-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0550 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.