Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

JOMANGY

51
Global rank
104 infographic chevron month
Month rank
202 infographic chevron week
Week rank

JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.

Backdoor
Type
Unknown
Origin
1 May, 2026
First seen
29 September, 2026
Last seen

How to analyze JOMANGY with ANY.RUN

Type
Unknown
Origin
1 May, 2026
First seen
29 September, 2026
Last seen

IOCs

IP addresses
91.189.91.64
160.119.69.4
185.125.190.57
89.106.83.205
204.44.93.119
118.107.1.203
104.249.10.144
91.92.240.17
205.185.115.131
142.251.127.94
120.76.143.184
130.17.8.71
194.150.166.178
185.27.134.24
205.185.113.69
195.177.94.112
188.114.96.3
132.243.212.233
83.171.226.136
45.74.3.37
Hashes
5b0b64839e19f838b8d09f3a5c598a27188b9e11e3c5c7eb793b9860fe83aeca
a8a284f377cb9f21c53e5553234ecb693dc4c2c38f3306b6cde4aead5e05e913
0b41f69e6564b9c89b1b344744c5b06eb4adc0e584028909286d2b936e1afed5
f8bf41177a5f5e808a7ccb648b51080b031f15ca8018d91a576263d6cc626eb6
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
319cff6e7a31f0f2a41c475dca42890aa5d19fe16017e2290f8c1d4e14f76481
aac73b3148f6d1d7111dbca32099f68d26c644c6813ae1e4f05f6579aa2663fe
46079c0a1b660fc187aafd760707f369d0b60d424d878c57685545a3fce95819
2eb96422375f1a7b687115b132a4005d2e7d3d5dc091fb0eb22a6471e712848e
5c9bc70586ad538b0df1fcf5d6f1f3527450ae16935aa34bd7eb494b4f1b2db9
72c639d1afda32a65143bcbe016fe5d8b46d17924f5f5190eb04efe954c1199a
7102f8d9d0f3f689129d7fe071b234077fba4dd3687071d1e2aeaa137b123f86
058eb7ce88c22d2ff7d3e61e6593ca4e3d6df449f984bf251d9432665e1517d1
f5183b8d7462c01031992267fe85680ab9c5b279bedc0b25ab219f7c2184766f
14f92b911f9fe774720461eec5bb4761ae6bfc9445c67e30bf624a8694b4b1da
e2ce89b3e68b003cb27e2c5652ccba073c8938bef194e51830539b2464a3f676
5494adf651fc64e3aa6c08e38165d8dbfec52056cdf4fadae90b76b0e6816a33
bf0386f6e9b4a35fefe5fe917e2be7c64867efe24521f18e4567f8af5f6dd5e5
129b343ff412f0b5af597face89caba3a70092e7ca758be9ebc7d1e6d1443c3c
b37602dbb924bb94df0d9745d13fcace8a6642397fb738fbe02a88f667f3ab66
Domains
google.com
connectivity-check.ubuntu.com
mitraperijinan.co.id
client.wns.windows.com
minpop.com
pizzariatrattoria.com
tapestryoftruth.com
r2---sn-a0jpm-a0mz.gvt1.com
www.intelligradeeducation.vicentecisnerospub.com
lavos.life
od.lk
www.microsoft.com
crazypianoswebshop.nl
universalmobility.pro
cloudstorage-hub.com
www.update.microsoft.com
geoxsecurity.ro
pub-5fd52250a6494c859025a3cd39713703.r2.dev
dl.360safe.com
rubburizee.es
URLs
http://connectivity-check.ubuntu.com/
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://activation-v2.sls.microsoft.com/slactivateproduct/slactivateproduct.asmx?configextension=retail
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://maper.info/26tkr5
https://www.google.com/
https://urlhaus.abuse.ch/downloads/text/
http://91.92.242.236/files-129312398/files/file_ad6ea8ff7c86f0ad.exe
http://91.92.242.236/files-129312398/files/file_7c23b7b64f4c1870.exe
http://107.174.33.14/96/img_182048.png
http://104.168.70.171/55/img_200534.png
http://5.175.169.207/img_113850.png
http://62.60.226.140/files/8351821253/nqa0sjr.exe
http://172.245.209.194/56/img_232634.png
http://193.90.12.80/ns1.jpg
http://193.90.12.80/ns3.jpg
Last Seen at
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

Inside JOMANGY: A Resilient FreePBX Malware Built to Survive Cleanup Attempts

Key Takeaways

  • JOMANGY is a newly documented PHP webshell first described in May 2026, developed by the financially motivated threat actor INJ3CTOR3, and targeting FreePBX-based VoIP phone systems with the explicit goal of generating toll fraud revenue.

  • Six self-reinforcing persistence channels make JOMANGY extraordinarily difficult to remove — any single surviving channel rebuilds the full infection within minutes, rendering partial remediation useless.

  • 18 hidden backdoor accounts (nine with full root-level privileges) are planted on every infected host, with account names deliberately mimicking legitimate FreePBX system accounts to evade manual audits.

  • Double-layer obfuscation (Base64 over ROT13) combined with active payload rotation gives JOMANGY near-zero antivirus detection rates at the time of initial deployment, making signature-based defenses unreliable for initial detection.

  • The financial risk is direct and immediate. JOMANGY's embedded toll fraud code uses the victim's own SIP trunks to generate call charges that are billed straight to the organization, with losses potentially reaching tens of thousands of dollars before the fraud is discovered.

  • Patch cadence is a critical gap. With hundreds of systems from the January 2026 campaign still infected five months later, organizations must treat FreePBX vulnerability patching as an urgent priority and never expose the admin panel directly to the internet.

  • Proactive threat intelligence is essential against rapidly evolving campaigns. Use ANY.RUN Threat Intelligence Lookup to instantly check your environment for known JOMANGY IOCs, C2 addresses, and campaign artifacts, and subscribe to ANY.RUN Threat Intelligence Feeds to automatically push fresh, machine-readable JOMANGY indicators into your SIEM, firewall, and EDR — staying ahead of the attacker's infrastructure rotation before it costs you.

    destinationIP:"160.119.69.4".

IP linked to JOMANGY in TI Lookup IP linked to JOMANGY in TI Lookup

What is JOMANGY?

JOMANGY is a PHP webshell family first identified and publicly documented in May 2026 by Cyble Research & Intelligence Labs (CRIL). It was deployed as part of an active campaign against internet-exposed FreePBX servers, the widely used open-source PBX (Private Branch Exchange) interface that manages Asterisk-based business phone systems.

The webshell's most defining characteristic is its self-healing architecture. Rather than relying on a single method of persistence, JOMANGY establishes six independent channels that protect and restore each other. If an administrator removes one component, the remaining channels automatically rebuild the full infection, typically within minutes. This design makes partial remediation functionally useless.

Beyond persistence, JOMANGY carries live toll fraud code embedded directly into every deployed instance. This code is capable of initiating outbound phone calls through the victim's own SIP trunks, routing them to premium-rate numbers controlled by the attacker. The victim's carrier then bills the victim for all those calls — sometimes accumulating thousands of dollars in fraudulent charges before the fraud is even detected.

JOMANGY is deployed alongside ZenharR, another webshell previously attributed to the INJ3CTOR3 actor lineage, and a component called license.php — a privileged PHP executor embedded into FreePBX's high-availability infrastructure that operates without authentication controls.

Every JOMANGY sample recovered during analysis carries the same hardcoded watermark string — trace_e1ebf9066a951be519a24140711839ea — tying all known instances back to a single development source and confirming the campaign's centralized origin.

ANY.RUN Interactive Sandbox lets analysts investigate JOMANGY behavior in real time, validate detection coverage, and observe webshell deployment, persistence mechanisms, and outbound C2 activity.

View analysis

JOMANGY detonated in Interactive Sandbox JOMANGY detonated in Interactive Sandbox_

MITRE ATT&CK techniques observed include:

  • 𝗣𝗲𝗿𝘀𝗶𝘀𝘁𝗲𝗻𝗰𝗲 via Cron jobs and Unix shell configuration abuse;
  • 𝗗𝗲𝗳𝗲𝗻𝘀𝗲 𝗲𝘃𝗮𝘀𝗶𝗼𝗻 through log clearing, timestomping, and firewall modification;
  • 𝗖𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹 𝗮𝗰𝗰𝗲𝘀𝘀 targeting /etc/passwd and /etc/shadow;
  • 𝗖𝗼𝗺𝗽𝗲𝘁𝗶𝘁𝗶𝘃𝗲 𝗲𝘃𝗶𝗰𝘁𝗶𝗼𝗻 of other webshells from compromised systems;
  • 𝗩𝗼𝗜𝗣/𝗦𝗜𝗣 𝗮𝗯𝘂𝘀𝗲 supporting toll fraud operations.

MITRE ATT&CK techniques observed in JOMANGY MITRE ATT&CK techniques observed in JOMANGY

The execution chain follows the sequence:

  • Vulnerable FreePBX instance;
  • Exploit public vulnerabilities;
  • Bash stager deployment;
  • JOMANGY webshell deployment;
  • Multiple persistence mechanisms;
  • Self-healing loop;
  • VoIP/SIP abuse.

The Sandbox completes a malware sample analysis with actionable Tier 1 report including an AI summary and AI recommendations on detection and containment.

Tier 1 report abstract Tier 1 report (abstract)

How JOMANGY Threatens Businesses and Organizations

JOMANGY presents several distinct and compounding threats to any organization running FreePBX infrastructure:

Financial harm through toll fraud. By routing calls through compromised SIP trunks to international premium-rate numbers (a scheme known as International Revenue Share Fraud (IRSF)) attackers generate revenue while the victim receives the bill from their telecom carrier.

Persistent, near-unremovable system compromise. JOMANGY's six-layer persistence model means that cleaning an infection is not a matter of deleting a few files. As documented by researchers, even 700 of the systems compromised in the January 2026 campaign wave remained infected five months after public disclosure, despite patches being available.

Complete administrative control. The 18 backdoor accounts planted by JOMANGY (nine of them with root-equivalent (UID-0) privileges) give attackers persistent, privileged access to the underlying OS. Account names are deliberately disguised to blend into the legitimate account inventory (e.g., asterisk, freepbxuser, spamfilter), making manual detection extremely difficult without specialized tooling.

Competitive territorial control. JOMANGY's dropper actively removes over 50 competing webshell signatures and blocks 11 rival C2 IP addresses, ensuring that the compromised system becomes the exclusive property of INJ3CTOR3. This behavior reflects the professionalization of the VoIP fraud underground, where compromised PBX access is a commodity with real market value.

Near-zero AV detection at deployment. Because the attacker actively rotates the payload contents using double-layer obfuscation (Base64 over ROT13), JOMANGY typically achieves near-zero detection rates across major antivirus engines at the time of initial deployment, giving the attack a wide window of opportunity before defenses catch up.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most Vulnerable?

JOMANGY primarily targets organizations operating internet-facing FreePBX infrastructure.

Most Vulnerable Sectors Industries threatened by JOMANGY Industries threatened by JOMANGY

The attacker's C2-hosted reconnaissance inventory of 3,080 IP addresses, approximately 39% of which pointed to Alibaba Cloud infrastructure, indicates a globally distributed, opportunistic campaign targeting organizations across the Asia-Pacific region, Latin America, and the Middle East, as well as Europe and North America.

Any organization that has not recently audited its FreePBX version, restricted web panel access, or reviewed its SIP trunk usage for anomalies should treat this as an urgent action item.

How JOMANGY Gets Into Systems and Spreads

JOMANGY gains initial access by exploiting vulnerabilities in FreePBX's web management interface. Researchers identified two candidate CVEs as likely entry points for the 2026 campaign:

  • CVE-2025-64328 — A post-authentication command injection vulnerability in the FreePBX Endpoint Manager's administrative interface, previously exploited in the January 2026 EncystPHP campaign.

  • CVE-2025-57819 — A pre-authentication SQL injection vulnerability in the FreePBX Endpoint module via cron jobs, with a public proof-of-concept from WatchTowr Labs whose artifacts the JOMANGY dropper explicitly attempts to clean up.

Once initial access is achieved, a multi-stage Bash dropper is deployed to the host. The dropper performs the following sequence:

  • Evicts over 50 competing webshell signatures and blocks 11 rival C2 IP addresses via firewall rules, eliminating competition and monopolizing the host.
  • Deletes all artifacts from INJ3CTOR3's own prior January 2026 campaign, migrating the active botnet to new infrastructure cleanly.
  • Drops the JOMANGY webshell across multiple locations in the FreePBX web root — more than 12 distinct file paths — many protected with chattr +i to make them immutable even to root.
  • Deploys ZenharR alongside JOMANGY for additional remote command execution capability.
  • Plants 18 backdoor accounts (nine UID-0, eight service-tier, one MySQL-injected FreePBX panel account).
  • Establishes six independent persistence channels.
  • Connects to the C2 server to report the new infection and begin receiving toll fraud instructions.

The malware also replicates JOMANGY into 15 additional locations within the web root as part of its propagation logic, ensuring maximum redundancy. The C2 server hosts a file called people2.txt containing 3,080 target IP addresses, representing the automated reconnaissance output used to feed new exploitation attempts.

How Does JOMANGY Malware Function?

JOMANGY's operation can be broken into three functional domains: evasion, persistence, and monetization.

Evasion

Every JOMANGY sample uses double-layer obfuscation. An outer Base64 encoding wraps a PHP string, which when decoded applies the ROT13 cipher to a second encoded layer before executing the result on the server. The threat actor actively rotates the payload contents between deployments, which produces distinct file hashes across samples and ensures near-zero antivirus detection rates at the time of initial deployment. The consistent internal watermark (trace_e1ebf9066a951be519a24140711839ea) is the forensic thread linking all variants to a common source despite the hash diversity.

Persistence (Six Independent Channels)

The six persistence mechanisms are designed so that any single surviving channel can fully rebuild the infection:

  • Cron-based C2 polling — A cron job polls the attacker's C2 server every one to three minutes, ready to receive new commands or re-download components.
  • Shell profile injection — Malicious code is injected into shell profile files, firing whenever root logs in or the system reboots.
  • Immutable crontab backups — Eight crontab backup copies are protected with chattr +i (making them undeletable without removing the immutable flag first), monitored by two dedicated restore cron loops that continuously verify and repair the others.
  • Process watchdog — A dedicated watchdog process monitors for the absence of the beacon process and immediately re-downloads the dropper if it disappears.
  • Immutable webshell copies — JOMANGY is replicated across more than twelve web root paths, many locked immutable, so that a single HTTP request to any surviving copy rebuilds the full infection stack.
  • Self-reinstalling PHP executor (license.php) — A PHP executor embedded within FreePBX's high-availability (HA) module provides privileged command execution independently of all other channels. It contains no authentication controls and relies on remotely supplied format-string placeholders before activation — making it a particularly dangerous backstop.

Monetization (Toll Fraud)

Every deployed JOMANGY instance carries active VoIP toll fraud code. Attackers use Asterisk CLI commands — such as asterisk -rx "channel originate Local/@" — to initiate outbound calls through the victim's own SIP trunks. These calls are routed to international premium-rate numbers (IPRNs) controlled by the attacker. The victim's telecom carrier charges the victim's account for all generated call volume. This method generates revenue with minimal operational overhead and leaves no ransomware artifacts for incident responders to follow.

How Businesses Can Use ANY.RUN’s Threat Intelligence Feeds and TI Lookup Against JOMANGY

Understanding a threat is only half the battle: organizations need actionable intelligence to defend against it proactively. ANY.RUN's Threat Intelligence Feeds and Threat Intelligence Lookup are purpose-built for exactly this kind of defense.

ANY.RUN Threat Intelligence Feeds deliver a continuously refreshed stream of high-confidence, machine-readable IOCs in formats compatible with SIEMs, firewalls, EDR platforms, and SOAR playbooks.

For a campaign like JOMANGY, where the attacker actively rotates payload hashes and migrates C2 infrastructure, having a real-time feed that captures fresh indicators as the campaign evolves is critical. Security teams can automatically block newly identified JOMANGY C2 addresses, flag access attempts to known malicious paths in the FreePBX web root, and alert on behavioral indicators such as the characteristic cron injection patterns used by the malware.

TI Feeds benefits and integration TI Feeds benefits and integration

ANY.RUN Threat Intelligence Lookup allows security teams to instantly query a continuously updated threat intelligence database for indicators of compromise (IOCs) directly associated with JOMANGY and the broader INJ3CTOR3 campaign.

Security analysts can search for known malicious IP addresses (including the 3,080-entry target inventory hosted on JOMANGY's C2), file hashes of JOMANGY and ZenharR samples, the campaign's unique watermark string (trace_e1ebf9066a951be519a24140711839ea), suspicious file paths dropped during infection, and known C2 domain and infrastructure details.

TI Lookup reveals two active JOMANGY infrastructure clusters tied to attacker-controlled C2 servers, with activity traced back to April 2026. This visibility helps threat hunters uncover related activity, identify compromised environments, and track infrastructure reuse across campaigns:

destinationIP:"160.119.69.4" OR destinationIP:"45.95.147.178".

JOMANGY infrastructure in TI Lookup JOMANGY infrastructure in TI Lookup

Organizations should also:

  • Patch FreePBX systems promptly;
  • Restrict internet exposure of management interfaces;
  • Monitor SIP activity for unusual call patterns;
  • Enable multi-factor authentication;
  • Audit privileged accounts regularly;
  • Monitor cron jobs and startup scripts;
  • Use EDR and server monitoring solutions;
  • Segment VoIP infrastructure from business-critical systems;
  • Rebuild compromised systems from clean images when infection is confirmed.

Researchers emphasize that partial cleanup may be ineffective due to JOMANGY's self-healing capabilities.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

JOMANGY represents a sophisticated evolution of VoIP-focused malware. While its primary objective is financial gain through toll fraud, its extensive persistence mechanisms, hidden accounts, and self-healing architecture make it a serious threat to organizations relying on FreePBX infrastructure.

For defenders, rapid visibility into malicious infrastructure, continuous threat intelligence, and proactive hunting are critical for detecting attacks before they result in substantial financial losses or long-term compromise. Combining strong patch management with threat intelligence-driven monitoring can significantly reduce exposure to emerging threats such as JOMANGY.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

FlowerStorm screenshot
FlowerStorm
flowerstorm
FlowerStorm is a phishing-as-a-service (PhaaS) platform used by cybercriminals to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA) protections through adversary-in-the-middle (AiTM) attacks. Emerging after the disruption of Rockstar2FA in late 2024, FlowerStorm rapidly gained popularity among attackers targeting enterprises across North America and Europe.
Read More
Pay2Key screenshot
Pay2Key is a ransomware strain primarily written in C++ for Windows (with recent Linux variants), attributed to Iranian-linked actors, notably the Fox Kitten APT group (also known as UNC757 or related operations). First observed in late 2020, it employs double-extortion tactics (encrypting files and threatening to leak stolen data) while showing signs of both financial and state-aligned motivations. It has resurfaced in campaigns targeting Western organizations, including rapid encryption attacks on healthcare.
Read More
ValleyRAT screenshot
ValleyRAT
valleyrat
ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.
Read More
Xeno RAT screenshot
Xeno RAT
xenorat
Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.
Read More
Spyware screenshot
Spyware
spyware
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Read More
RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More