Also known as: tracked as, No associated aliases, LummaC2 Stealer
INJ3CTOR3 first appeared around 2020, focusing on monetizing vulnerabilities in the VoIP ecosystem. It leverages documented weaknesses such as CVE-2019‑19006 (authentication bypass), CVE-2021‑45461 (remote code execution) and the newer CVE‑2025‑64328 (local privilege escalation) to gain initial access to FreePBX servers. Once inside, the actor deploys custom PHP web shells, notably the EncystPHP and JOMANGY families, that embed multiple persistence mechanisms. These include self‑repair cron jobs, alternate file locations, registry edits (on Windows), and scheduled tasks that allow the shell to survive host restarts or cleanup attempts. Operationally, INJ3CTOR3 conducts toll‑fraud by enumerating SIP trunks, extracting authentication credentials from configuration files such as "*.conf", and rerouting calls to siphon millions of dollars in service charges. Beyond direct financial gain, the group reuses stolen credentials for lateral movement into critical infrastructure such as energy company dispatch centers, thereby expanding its foothold. The actor’s methodology extends beyond FreePBX; it actively scans for other open VoIP solutions (Elastix, Issabel) and deploys brute‑force scripts to compromise them. Control of compromised hosts is maintained via HTTP‑based web shell commands or PowerShell back‑doors connected to persistent domain‑owned C2 servers.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
INJ3CTOR3 is a financially motivated adversary that exploits known CVEs in FreePBX and other VoIP platforms to deploy resilient PHP web shells. After compromising the system, it harvests SIP credentials, manipulates call routing tables for toll‑fraud payouts, and later moves laterally within energy, defense and critical‑infrastructure networks. The group targets organizations with publicly exposed telecommunication services in Belarus, Brazil and China.
Goals & Targeting
The primary objective of INJ3CTOR3 is monetisation through toll‑fraud, targeting organisations that rely on VoIP infrastructure for communications. Targeted sectors include energy, telecommunications, and critical infrastructure where SIP trunk usage is common. The actor preferentially compromises systems exposed in Belarus, Brazil, and China—countries with widespread adoption of open‑source VoIP platforms and often limited patching rigor. Typical victims are VoIP providers, utilities dispatch centres and other organisations that manage SIP credentials for their network operations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
INJ3CTOR3 operates on a low‑frequency, high‑impact campaign model focused on sustaining long‑term economic exploitation rather than rapid takedowns. The actor repeatedly reuses older CVEs (e.g., CVE-2019-19006) while also deploying newly discovered zero‑days to maintain access to compromised networks. Victims are usually medium‑to‑large organisations with critical communication services; the attacker’s persistence mechanisms allow it to remain undetected for extended periods, enabling continuous fraud and lateral expansion within energy, defense and telecom infrastructures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the exploitation of FreePBX CVEs and the deployment of custom PHP web shells, supported by multiple independent sources including Fortinet analysis. Moderate confidence regarding lateral movement into energy and defense sectors; evidence is anecdotal and lacks direct attribution documentation. Confidence about targeted countries (BY, BR, CN) is derived solely from threat actor statement with no corroborating external data. Overall, the core technical capabilities are well‑documented, but broader operational context may be incomplete.
No campaigns linked yet.
No observed data linked yet.
12
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
4
Tactics