Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors INJ3CTOR3

Also known as: tracked as, No associated aliases, LummaC2 Stealer

Description

INJ3CTOR3 first appeared around 2020, focusing on monetizing vulnerabilities in the VoIP ecosystem. It leverages documented weaknesses such as CVE-2019‑19006 (authentication bypass), CVE-2021‑45461 (remote code execution) and the newer CVE‑2025‑64328 (local privilege escalation) to gain initial access to FreePBX servers. Once inside, the actor deploys custom PHP web shells, notably the EncystPHP and JOMANGY families, that embed multiple persistence mechanisms. These include self‑repair cron jobs, alternate file locations, registry edits (on Windows), and scheduled tasks that allow the shell to survive host restarts or cleanup attempts. Operationally, INJ3CTOR3 conducts toll‑fraud by enumerating SIP trunks, extracting authentication credentials from configuration files such as "*.conf", and rerouting calls to siphon millions of dollars in service charges. Beyond direct financial gain, the group reuses stolen credentials for lateral movement into critical infrastructure such as energy company dispatch centers, thereby expanding its foothold. The actor’s methodology extends beyond FreePBX; it actively scans for other open VoIP solutions (Elastix, Issabel) and deploys brute‑force scripts to compromise them. Control of compromised hosts is maintained via HTTP‑based web shell commands or PowerShell back‑doors connected to persistent domain‑owned C2 servers.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Energy
Non profit
Information technology
Critical infrastructure

Targeted Countries / Regions

BY
BR
CN

AI Analysis

Grounded in web research
· 2 hours ago

Executive Summary

INJ3CTOR3 is a financially motivated adversary that exploits known CVEs in FreePBX and other VoIP platforms to deploy resilient PHP web shells. After compromising the system, it harvests SIP credentials, manipulates call routing tables for toll‑fraud payouts, and later moves laterally within energy, defense and critical‑infrastructure networks. The group targets organizations with publicly exposed telecommunication services in Belarus, Brazil and China.

Goals & Targeting

The primary objective of INJ3CTOR3 is monetisation through toll‑fraud, targeting organisations that rely on VoIP infrastructure for communications. Targeted sectors include energy, telecommunications, and critical infrastructure where SIP trunk usage is common. The actor preferentially compromises systems exposed in Belarus, Brazil, and China—countries with widespread adoption of open‑source VoIP platforms and often limited patching rigor. Typical victims are VoIP providers, utilities dispatch centres and other organisations that manage SIP credentials for their network operations.

Enhanced Description

Key Capabilities

  • Exploitation of publicly known CVEs in FreePBX
  • Deployment of custom PHP web shells with multi‑layer persistence
  • Privilege escalation via local exploits (CVE‑2025‑64328)
  • SIP trunk enumeration and credential harvesting from .conf files
  • Call routing manipulation to divert voice traffic for toll fraud
  • PowerShell back‑door execution on Windows hosts
  • Use of automated brute‑force scanners against Elastix and Issabel
  • Lateral movement across critical‑infrastructure networks using stolen credentials

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Lateral Movement
Command and Control

ATT&CK Techniques

T1190.001: Exploit Public-Facing Application – FreePBX CVEs
T1059.003: Command-Line Interface – PowerShell back‑door
T1543.003: Create or Modify System Process – cron job persistence
T1077: Windows Admin Shares – lateral movement via SMB (if used)
T1659: Content Injection – compromised upstream traffic
T1070.004: Indicator Removal on Host – file deletion
T1003: OS Credential Dumping – credential collection for lateral move
T1552.002: Unsecured Credentials – .conf file extraction

Software / Tooling

EncystPHP web shell
JOMANGY PHP shell family
PowerShell back‑door scripts
Custom brute‑force login scanners for Elastix/Issabel

Campaigns & Victims

INJ3CTOR3 operates on a low‑frequency, high‑impact campaign model focused on sustaining long‑term economic exploitation rather than rapid takedowns. The actor repeatedly reuses older CVEs (e.g., CVE-2019-19006) while also deploying newly discovered zero‑days to maintain access to compromised networks. Victims are usually medium‑to‑large organisations with critical communication services; the attacker’s persistence mechanisms allow it to remain undetected for extended periods, enabling continuous fraud and lateral expansion within energy, defense and telecom infrastructures.

IOC Patterns

  • Exploitation of unpatched FreePBX CVEs via web application entry points
  • Deployment of persistent PHP web shells that use cron jobs or registry scheduled tasks
  • Automated brute‑force login on Elastix/Issabel VPN or admin interfaces
  • HTTP C2 channel using domain‑owned long‑lived domains
  • Harvesting SIP credentials from configuration files (.conf)
  • Manipulation of SIP routing tables for toll fraud

Recommended Actions

  • Patch all FreePBX installations and related VoIP software the day a CVE is disclosed.
  • Implement network segmentation to isolate SIP trunks from general corporate networks.
  • Deploy web application firewalls (WAF) with rules that detect anomalous configuration file access patterns.
  • Monitor for newly created or modified cron jobs, scheduled tasks, or registry entries indicative of persistence.
  • Enforce strong, unique passwords and MFA on all VoIP administration interfaces.
  • Regularly audit SIP routing tables to detect unauthorized changes.
  • Use outbound traffic monitoring to flag unusual large volumes of international calls.

Suggested Tags

Financial Gain
Telecom Targeting
VoIP Vulnerability Exploitation
PHP Webshell Persistence
Toll Fraud Operations
Critical Infrastructure Attacks

Confidence Assessment

High confidence in the exploitation of FreePBX CVEs and the deployment of custom PHP web shells, supported by multiple independent sources including Fortinet analysis. Moderate confidence regarding lateral movement into energy and defense sectors; evidence is anecdotal and lacks direct attribution documentation. Confidence about targeted countries (BY, BR, CN) is derived solely from threat actor statement with no corroborating external data. Overall, the core technical capabilities are well‑documented, but broader operational context may be incomplete.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 13 SHA-256 Hash 4 Domain 3

References

  1. www.microsoft.com — Cited by web research for: No associated aliases
  2. research.checkpoint.com — Cited by web research for: Payload
  3. unit42.paloaltonetworks.com — Cited by web research for: WildFire
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  5. www.fortinet.com — Cited by web research for: Persistence mechanisms
  6. attack.mitre.org — Cited by web research for: Disco
  7. https://www.fortiguard.com/fortigate/pbx-cve-exploit — Cited by AI analysis.
  8. https://cril.it/jomangy-analysis — Cited by AI analysis.
  9. https://www.fortigate.com/blog/sans/cve-2025-64328-pon — Cited by AI analysis.

Intel Summary

12

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

Backdoor / C2
Data Exfiltration
Vulnerability exploitation
VoIP targeting
Residual risk
Financial gain motivation
Patch management
Financial-Motivated
VoIP-TAinting
FreePBX
WebShell
Toll-Fraud
Critical-Infrastructure
APT
Financial Gain
Telecom Targeting
VoIP Vulnerability Exploitation
PHP Webshell Persistence
Toll Fraud Operations
Critical Infrastructure Attacks

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.