INJ3CTOR3 is a financially motivated threat actor focused on compromising VoIP and PBX infrastructure, particularly FreePBX, Sangoma PBX, and Elastix environments, to monetize access through telephony abuse and toll fraud. The group has been active since at least 2020 and has repeatedly exploited vulnerabilities in internet-exposed voice systems, including CVE-2019-19006, CVE-2021-45461, CVE-2025-64328, and likely CVE-2025-57819. Security reporting consistently links the actor to campaigns against telecommunications infrastructure rather than to a confirmed nation-state sponsor. The actor is known for deploying PHP web shells such as JOMANGY and EncystPHP after exploitation. These payloads provide remote command execution and long-term access, and are engineered for resilience through layered persistence. Observed persistence methods include recurring cron-based reinstallation, shell profile modification, watchdog processes, redundant web shell placement across multiple directories, privileged PHP execution paths, SSH key injection, and creation of hidden or root-equivalent backdoor accounts. Some campaigns used immutable file attributes and multiple mutually reinforcing persistence channels, making partial cleanup ineffective and allowing rapid reinfection. INJ3CTOR3 also demonstrates strong defense-evasion tradecraft. Reported behaviors include obfuscation of PHP payloads, timestamp spoofing, deletion of logs, removal of vulnerable modules after exploitation, restoration of permissions to avoid operational disruption, and active removal of competing web shells or other criminal tooling from compromised hosts. The actor has harvested configuration and credential material from PBX environments, manipulated user accounts and passwords, and maintained privileged access for continued control. Operationally, INJ3CTOR3 conducts mass exploitation of exposed VoIP systems at scale, using scanning and automated targeting to compromise large numbers of hosts globally. Post-compromise activity centers on abuse of SIP trunks and PBX functionality to generate unauthorized outbound calls and related fraud. Some reporting also notes the potential for deeper post-exploitation and network pivoting from compromised PBX servers. Known aliases in the supplied material are limited to INJ3CTOR3.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Forensics point to two high-confidence flaws tracked as CVE-2025-64328 and CVE-2025-57819. Many systems remain exposed because administrators fail to apply patches promptly.
...INJ3CTOR3, a financially motivated hacker group first identified in 2020 when they targeted CVE-2019-19006 in FreePBX systems.
In 2022, the threat actor evolved their tactics by shifting focus to Elastix systems through the exploitation of CVE-2021-45461.
Forensics point to two high-confidence flaws tracked as CVE-2025-64328 and CVE-2025-57819. Many systems remain exposed because administrators fail to apply patches promptly.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated exploitation of exposed FreePBX/VoIP servers, using the JOMANGY webshell to enable toll fraud and maintain resilient persistence across compromised systems.
Conducting financially motivated mass exploitation of internet-exposed FreePBX/VoIP systems for toll fraud, using the JOMANGY webshell and highly resilient multi-layer persistence to maintain access.
Linked to exploitation of CVE-2025-64328 against Sangoma FreePBX Endpoint Manager to deploy PHP web shells (including EncystPHP) for persistent remote access and follow-on payload delivery.
Opportunistic, automated mass-exploitation of internet-facing Sangoma FreePBX instances via CVE-2025-64328 to deploy persistent PHP web shells (notably EncystPHP) enabling remote command execution, persistence, and follow-on activity such as outbound call fraud and potential lateral movement/pivoting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.