🚨 𝗝𝗢𝗠𝗔𝗡𝗚𝗬 𝗪𝗲𝗯𝘀𝗵𝗲𝗹𝗹 𝗘𝗻𝗮𝗯𝗹𝗲𝘀 𝗟𝗼𝗻𝗴-𝗧𝗲𝗿𝗺 𝗖𝗼𝗺𝗽𝗿𝗼𝗺𝗶𝘀𝗲 𝗼𝗳 𝗩𝗼𝗜𝗣 𝗜𝗻𝗳𝗿𝗮𝘀𝘁𝗿𝘂𝗰𝘁𝘂𝗿𝗲
⚠️ #JOMANGY is an actively used PHP backdoor targeting FreePBX-based VoIP environments with stealth, self-recovery, and VoIP/SIP abuse capabilities.

Once deployed, it establishes persistent access, creates hidden root accounts, and abuses Asterisk/SIP services for toll fraud operations. Since VoIP systems are deeply integrated into enterprise environments, delayed detection can lead to prolonged unauthorized access, financial loss, and operational disruption.

❗️ The malware relies on stealth and defense-evasion techniques designed to survive cleanup attempts and complicate containment for SOC and IR teams once systems are compromised. MITRE ATT&CK techniques observed include:
🔹 𝗣𝗲𝗿𝘀𝗶𝘀𝘁𝗲𝗻𝗰𝗲 via Cron jobs and Unix shell configuration abuse
🔹 𝗗𝗲𝗳𝗲𝗻𝘀𝗲 𝗲𝘃𝗮𝘀𝗶𝗼𝗻 through log clearing, timestomping, and firewall modification
🔹 𝗖𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹 𝗮𝗰𝗰𝗲𝘀𝘀 targeting `/etc/passwd` and `/etc/shadow`
🔹 𝗖𝗼𝗺𝗽𝗲𝘁𝗶𝘁𝗶𝘃𝗲 𝗲𝘃𝗶𝗰𝘁𝗶𝗼𝗻 of other webshells from compromised systems
🔹 𝗩𝗼𝗜𝗣/𝗦𝗜𝗣 𝗮𝗯𝘂𝘀𝗲 supporting toll fraud operations

Execution chain:
Vulnerable FreePBX instance ➡️ Exploit public vulnerabilities ➡️ Bash stager deployment ➡️ JOMANGY webshell deployment ➡️ Multiple persistence mechanisms ➡️ Self-healing loop ➡️ VoIP/SIP abuse

👨‍💻 Using #ANYRUN Sandbox, investigate JOMANGY behavior in real time, validate detection coverage, and observe webshell deployment, persistence mechanisms, and outbound C2 activity: https://app.any.run/tasks/6c779f0e-e422-4ef5-9bc7-6a799480cc20/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktoservice&utm_term=280526

Earlier visibility into persistence and webshell behavior helps SOC teams accelerate containment and reduce attacker dwell time. IOCs in the comments 💬

🔍 #ANYRUN TI Lookup reveals two active JOMANGY infrastructure clusters tied to attacker-controlled C2 servers, with activity traced back to April 2026. This visibility helps threat hunters uncover related activity, identify compromised environments, and track infrastructure reuse across campaigns: https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktotilookup&utm_term=280526#%7B%2522query%2522:%2522destinationIP:%255C%2522160.119.69.4%255C%2522%2520OR%2520destinationIP:%255C%252245.95.147.178%255C%2522%2522,%2522dateRange%2522:180%7D

🚀 Scale your SOC’s triage and response with solutions trusted by 74 Fortune 100 companies and detect business risks earlier. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/?utm_source=mastodon&utm_medium=post&utm_campaign=jomangy_webshell&utm_content=linktoplans&utm_term=280526

#cybersecurity #infosec

URLs:
hxxp[://]160[.]119[.]69[.]4/x
hxxp[://]45[.]95[.]147[.]178/x
hxxp[://]45[.]95[.]147[.]178/z/post/noroot[.]php

IPs:
45[.]95[.]147[.]178
160[.]119[.]69[.]4

SHA256:
23a50a27395f2dba028c6d86ef135ba46cf9ebf60ea7c2d2c96dd55db6df9477
6bca44c29f2d84d49b6bd36f8339bd88d93980d145d9cda4251572828da13862
da38a0364c737af546a978d4cf71dccb51c837db5395577283c3c1605fa96cbb
347e9d05feb7736b15a1890c59e006b58f91a1545110398d80ef036fdb9cf4f2
57ca86c77f0e6c788f1aae7bfb4b66abf22c347ecd3a64af7fa22f726c819433
04c1141b36518c9965a831c68c6bfcbbb8d4d87c43dc15a1c94e4187f9baff5a
587248ce91e1596a000a46720e7326863f43680eab53c1a1aefc55e4be0c01d4
5f2118495bbb74f0946f1476465d717ec5b6f35bf629fd3423f785479fe61202
49b0327a9c426e173309f52357e0a45a2251a95455965ba1e4fa2a4b517d2591
798fe047f03fc3f2c90c7e0be764b6cfce47c8310697ec5a380b6ec6bad1f669
E86cc5a0cde3c8c06a54a03b5155099be836132269cfa458d5ee82165643674b