๐จ ๐๐ข๐ ๐๐ก๐๐ฌ ๐ช๐ฒ๐ฏ๐๐ต๐ฒ๐น๐น ๐๐ป๐ฎ๐ฏ๐น๐ฒ๐ ๐๐ผ๐ป๐ด-๐ง๐ฒ๐ฟ๐บ ๐๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ ๐ผ๐ณ ๐ฉ๐ผ๐๐ฃ ๐๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ
โ ๏ธ #JOMANGY is an actively used PHP backdoor targeting FreePBX-based VoIP environments with stealth, self-recovery, and VoIP/SIP abuse capabilities.
Once deployed, it establishes persistent access, creates hidden root accounts, and abuses Asterisk/SIP services for toll fraud operations. Since VoIP systems are deeply integrated into enterprise environments, delayed detection can lead to prolonged unauthorized access, financial loss, and operational disruption.
โ๏ธ The malware relies on stealth and defense-evasion techniques designed to survive cleanup attempts and complicate containment for SOC and IR teams once systems are compromised. MITRE ATT&CK techniques observed include:
๐น ๐ฃ๐ฒ๐ฟ๐๐ถ๐๐๐ฒ๐ป๐ฐ๐ฒ via Cron jobs and Unix shell configuration abuse
๐น ๐๐ฒ๐ณ๐ฒ๐ป๐๐ฒ ๐ฒ๐๐ฎ๐๐ถ๐ผ๐ป through log clearing, timestomping, and firewall modification
๐น ๐๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ฎ๐ฐ๐ฐ๐ฒ๐๐ targeting `/etc/passwd` and `/etc/shadow`
๐น ๐๐ผ๐บ๐ฝ๐ฒ๐๐ถ๐๐ถ๐๐ฒ ๐ฒ๐๐ถ๐ฐ๐๐ถ๐ผ๐ป of other webshells from compromised systems
๐น ๐ฉ๐ผ๐๐ฃ/๐ฆ๐๐ฃ ๐ฎ๐ฏ๐๐๐ฒ supporting toll fraud operations
Execution chain:
Vulnerable FreePBX instance โก๏ธ Exploit public vulnerabilities โก๏ธ Bash stager deployment โก๏ธ JOMANGY webshell deployment โก๏ธ Multiple persistence mechanisms โก๏ธ Self-healing loop โก๏ธ VoIP/SIP abuse
๐จโ๐ป Using #ANYRUN Sandbox, investigate JOMANGY behavior in real time, validate detection coverage, and observe webshell deployment, persistence mechanisms, and outbound C2 activity: https://app.any.run/tasks/6c779f0e-e422-4ef5-9bc7-6a799480cc20/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktoservice&utm_term=280526
Earlier visibility into persistence and webshell behavior helps SOC teams accelerate containment and reduce attacker dwell time. IOCs in the comments ๐ฌ
๐ #ANYRUN TI Lookup reveals two active JOMANGY infrastructure clusters tied to attacker-controlled C2 servers, with activity traced back to April 2026. This visibility helps threat hunters uncover related activity, identify compromised environments, and track infrastructure reuse across campaigns: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktotilookup&utm_term=280526#%7B%2522query%2522:%2522destinationIP:%255C%2522160.119.69.4%255C%2522%2520OR%2520destinationIP:%255C%252245.95.147.178%255C%2522%2522,%2522dateRange%2522:180%7D
๐ Scale your SOCโs triage and response with solutions trusted by 74 Fortune 100 companies and detect business risks earlier. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktoplans&utm_term=280526
#cybersecurity #infosec