Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

JOMANGY

53
Global rank
62 infographic chevron month
Month rank
101 infographic chevron week
Week rank
0
IOCs

JOMANGY is a PHP webshell and backdoor family targeting vulnerable FreePBX servers. It is designed to establish long-term access to compromised VoIP infrastructure, enable toll fraud, and survive remediation attempts through multiple self-reinforcing persistence mechanisms. Unlike many traditional webshells, JOMANGY employs a highly resilient architecture that can automatically restore itself even after partial removal.

Backdoor
Type
Unknown
Origin
1 May, 2026
First seen
24 August, 2026
Last seen

How to analyze JOMANGY with ANY.RUN

Type
Unknown
Origin
1 May, 2026
First seen
24 August, 2026
Last seen

IOCs

IP addresses
155.103.69.250
185.27.134.177
142.251.14.94
203.159.90.118
178.16.52.133
104.239.66.38
217.60.241.248
185.27.134.24
95.164.53.193
95.216.21.87
176.65.139.201
77.83.39.9
206.168.149.26
104.168.70.168
142.251.13.95
195.177.94.118
180.235.151.11
216.120.147.200
188.114.96.3
124.198.131.217
Hashes
81b2bd4ea98c8db66554fbc8d7637a1a69a130f331feb732b75caab4c4868fd5
837def894a069786ff70e524b6b9cc16a7d745954c20f4623b6e6783150e5d37
11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5
87c640d3184c17d3b446a72d5f13d643a774b4ecc7afbedfd4e8da7795ea8077
3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
3cff4ac91288a0ff0c13278e73b282a64e83d089c5a61a45d483194ab336b852
de185ee5d433e6cfbb2e5fcc903dbd60cc833a3ca5299f2862b253a41e7aa08c
20de375707692099b3132084695377ce5fec0aec05813dedcce094b8eda44386
34048abaa070ecc13b318cea31425f4ca3edd133d350318ac65259e6058c8b32
7bfbc8202b8cdbdcc597a0e789240f0dc0b0e94fa6597e576eaf436bc6223e18
cc5dacf370f324b77b50dddf5d995fd3c7b7a587cb2f55ac9f24c929d0cd531a
db85f2f94d4994283e1055057372594538ae11020389d966e45607413851d9e9
990586f2a2ba00d48b59bdd03d3c223b8e9fb7d7fab6d414bac2833eb1241ca2
60793c8592193cfbd00fd3e5263be4315d650ba4f9e4fda9c45a10642fd998be
7581edea33c1db0a49b8361e51e6291688601640e57d75909fb2007b2104fa4c
4a2d59993bce76790c6d923af81bf404f8e2cb73552e320113663b14cf78748c
d2a7999e234e33828888ad455baa6ab101d90323579abc1095b8c42f0f723b6f
62173a8fadd4bf4dd71ab89ea718754aa31620244372f0c5bbbae102e641a60e
3cce33d75d6fdae4e004d0bdf149320b3147482a9caf370079dcb9c191a1b260
f2fd8edb3271310fc2af0ffa72886b26094d3e3b5c3bb709269d2ec4b31285a4
Domains
ifeanyioluwatobi.wuaze.com
www.bing.com
maper.info
mainhold.duckdns.org
example.com
xpaywalletcdn.azureedge.net
shadowroute.io
eykrqioydzqaehcektgd.supabase.co
normandy.cdn.mozilla.net
nextjs2385.ngrok.io
config.edge.skype.com
firefox-settings-attachments.cdn.mozilla.net
savannahadventureslimited.com
meridia.rs
edge.microsoft.com
pub-8381079dd326488ba56aa107eec22aea.r2.dev
contile.services.mozilla.com
assets.msn.com
chrome-windows.ru
fonts.gstatic.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/ppsecure/deviceaddcredential.srf
https://maper.info/26tkr5
https://www.google.com/
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://urlhaus.abuse.ch/downloads/text/
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://196.251.107.186/clpmem.exe
http://62.60.226.140/files/7782139129/d40iw6t.exe
http://62.60.226.140/files/1372270670/jz4kcas.exe
http://196.251.107.186/2.7.exe
http://196.251.107.186/clp.exe
http://217.60.241.142/bin/screenconnect.clientsetup.exe
http://91.92.242.236/files-129312398/files/file_ba3c4b02363471d3.exe
http://62.60.226.140/files/7782139129/tz2szvl.exe
http://178.16.54.109/spamget.exe
http://91.92.242.236/files-129312398/files/file_28ae045da50f3847.exe
http://62.60.226.140/files/7154708060/echfkbj.exe
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2585
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7440
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10551
comments 0

Inside JOMANGY: A Resilient FreePBX Malware Built to Survive Cleanup Attempts

Key Takeaways

  • JOMANGY is a newly documented PHP webshell first described in May 2026, developed by the financially motivated threat actor INJ3CTOR3, and targeting FreePBX-based VoIP phone systems with the explicit goal of generating toll fraud revenue.

  • Six self-reinforcing persistence channels make JOMANGY extraordinarily difficult to remove — any single surviving channel rebuilds the full infection within minutes, rendering partial remediation useless.

  • 18 hidden backdoor accounts (nine with full root-level privileges) are planted on every infected host, with account names deliberately mimicking legitimate FreePBX system accounts to evade manual audits.

  • Double-layer obfuscation (Base64 over ROT13) combined with active payload rotation gives JOMANGY near-zero antivirus detection rates at the time of initial deployment, making signature-based defenses unreliable for initial detection.

  • The financial risk is direct and immediate. JOMANGY's embedded toll fraud code uses the victim's own SIP trunks to generate call charges that are billed straight to the organization, with losses potentially reaching tens of thousands of dollars before the fraud is discovered.

  • Patch cadence is a critical gap. With hundreds of systems from the January 2026 campaign still infected five months later, organizations must treat FreePBX vulnerability patching as an urgent priority and never expose the admin panel directly to the internet.

  • Proactive threat intelligence is essential against rapidly evolving campaigns. Use ANY.RUN Threat Intelligence Lookup to instantly check your environment for known JOMANGY IOCs, C2 addresses, and campaign artifacts, and subscribe to ANY.RUN Threat Intelligence Feeds to automatically push fresh, machine-readable JOMANGY indicators into your SIEM, firewall, and EDR — staying ahead of the attacker's infrastructure rotation before it costs you.

    destinationIP:"160.119.69.4".

IP linked to JOMANGY in TI Lookup IP linked to JOMANGY in TI Lookup

What is JOMANGY?

JOMANGY is a PHP webshell family first identified and publicly documented in May 2026 by Cyble Research & Intelligence Labs (CRIL). It was deployed as part of an active campaign against internet-exposed FreePBX servers, the widely used open-source PBX (Private Branch Exchange) interface that manages Asterisk-based business phone systems.

The webshell's most defining characteristic is its self-healing architecture. Rather than relying on a single method of persistence, JOMANGY establishes six independent channels that protect and restore each other. If an administrator removes one component, the remaining channels automatically rebuild the full infection, typically within minutes. This design makes partial remediation functionally useless.

Beyond persistence, JOMANGY carries live toll fraud code embedded directly into every deployed instance. This code is capable of initiating outbound phone calls through the victim's own SIP trunks, routing them to premium-rate numbers controlled by the attacker. The victim's carrier then bills the victim for all those calls — sometimes accumulating thousands of dollars in fraudulent charges before the fraud is even detected.

JOMANGY is deployed alongside ZenharR, another webshell previously attributed to the INJ3CTOR3 actor lineage, and a component called license.php — a privileged PHP executor embedded into FreePBX's high-availability infrastructure that operates without authentication controls.

Every JOMANGY sample recovered during analysis carries the same hardcoded watermark string — trace_e1ebf9066a951be519a24140711839ea — tying all known instances back to a single development source and confirming the campaign's centralized origin.

ANY.RUN Interactive Sandbox lets analysts investigate JOMANGY behavior in real time, validate detection coverage, and observe webshell deployment, persistence mechanisms, and outbound C2 activity.

View analysis

JOMANGY detonated in Interactive Sandbox JOMANGY detonated in Interactive Sandbox_

MITRE ATT&CK techniques observed include:

  • 𝗣𝗲𝗿𝘀𝗶𝘀𝘁𝗲𝗻𝗰𝗲 via Cron jobs and Unix shell configuration abuse;
  • 𝗗𝗲𝗳𝗲𝗻𝘀𝗲 𝗲𝘃𝗮𝘀𝗶𝗼𝗻 through log clearing, timestomping, and firewall modification;
  • 𝗖𝗿𝗲𝗱𝗲𝗻𝘁𝗶𝗮𝗹 𝗮𝗰𝗰𝗲𝘀𝘀 targeting /etc/passwd and /etc/shadow;
  • 𝗖𝗼𝗺𝗽𝗲𝘁𝗶𝘁𝗶𝘃𝗲 𝗲𝘃𝗶𝗰𝘁𝗶𝗼𝗻 of other webshells from compromised systems;
  • 𝗩𝗼𝗜𝗣/𝗦𝗜𝗣 𝗮𝗯𝘂𝘀𝗲 supporting toll fraud operations.

MITRE ATT&CK techniques observed in JOMANGY MITRE ATT&CK techniques observed in JOMANGY

The execution chain follows the sequence:

  • Vulnerable FreePBX instance;
  • Exploit public vulnerabilities;
  • Bash stager deployment;
  • JOMANGY webshell deployment;
  • Multiple persistence mechanisms;
  • Self-healing loop;
  • VoIP/SIP abuse.

The Sandbox completes a malware sample analysis with actionable Tier 1 report including an AI summary and AI recommendations on detection and containment.

Tier 1 report abstract Tier 1 report (abstract)

How JOMANGY Threatens Businesses and Organizations

JOMANGY presents several distinct and compounding threats to any organization running FreePBX infrastructure:

Financial harm through toll fraud. By routing calls through compromised SIP trunks to international premium-rate numbers (a scheme known as International Revenue Share Fraud (IRSF)) attackers generate revenue while the victim receives the bill from their telecom carrier.

Persistent, near-unremovable system compromise. JOMANGY's six-layer persistence model means that cleaning an infection is not a matter of deleting a few files. As documented by researchers, even 700 of the systems compromised in the January 2026 campaign wave remained infected five months after public disclosure, despite patches being available.

Complete administrative control. The 18 backdoor accounts planted by JOMANGY (nine of them with root-equivalent (UID-0) privileges) give attackers persistent, privileged access to the underlying OS. Account names are deliberately disguised to blend into the legitimate account inventory (e.g., asterisk, freepbxuser, spamfilter), making manual detection extremely difficult without specialized tooling.

Competitive territorial control. JOMANGY's dropper actively removes over 50 competing webshell signatures and blocks 11 rival C2 IP addresses, ensuring that the compromised system becomes the exclusive property of INJ3CTOR3. This behavior reflects the professionalization of the VoIP fraud underground, where compromised PBX access is a commodity with real market value.

Near-zero AV detection at deployment. Because the attacker actively rotates the payload contents using double-layer obfuscation (Base64 over ROT13), JOMANGY typically achieves near-zero detection rates across major antivirus engines at the time of initial deployment, giving the attack a wide window of opportunity before defenses catch up.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most Vulnerable?

JOMANGY primarily targets organizations operating internet-facing FreePBX infrastructure.

Most Vulnerable Sectors Industries threatened by JOMANGY Industries threatened by JOMANGY

The attacker's C2-hosted reconnaissance inventory of 3,080 IP addresses, approximately 39% of which pointed to Alibaba Cloud infrastructure, indicates a globally distributed, opportunistic campaign targeting organizations across the Asia-Pacific region, Latin America, and the Middle East, as well as Europe and North America.

Any organization that has not recently audited its FreePBX version, restricted web panel access, or reviewed its SIP trunk usage for anomalies should treat this as an urgent action item.

How JOMANGY Gets Into Systems and Spreads

JOMANGY gains initial access by exploiting vulnerabilities in FreePBX's web management interface. Researchers identified two candidate CVEs as likely entry points for the 2026 campaign:

  • CVE-2025-64328 — A post-authentication command injection vulnerability in the FreePBX Endpoint Manager's administrative interface, previously exploited in the January 2026 EncystPHP campaign.

  • CVE-2025-57819 — A pre-authentication SQL injection vulnerability in the FreePBX Endpoint module via cron jobs, with a public proof-of-concept from WatchTowr Labs whose artifacts the JOMANGY dropper explicitly attempts to clean up.

Once initial access is achieved, a multi-stage Bash dropper is deployed to the host. The dropper performs the following sequence:

  • Evicts over 50 competing webshell signatures and blocks 11 rival C2 IP addresses via firewall rules, eliminating competition and monopolizing the host.
  • Deletes all artifacts from INJ3CTOR3's own prior January 2026 campaign, migrating the active botnet to new infrastructure cleanly.
  • Drops the JOMANGY webshell across multiple locations in the FreePBX web root — more than 12 distinct file paths — many protected with chattr +i to make them immutable even to root.
  • Deploys ZenharR alongside JOMANGY for additional remote command execution capability.
  • Plants 18 backdoor accounts (nine UID-0, eight service-tier, one MySQL-injected FreePBX panel account).
  • Establishes six independent persistence channels.
  • Connects to the C2 server to report the new infection and begin receiving toll fraud instructions.

The malware also replicates JOMANGY into 15 additional locations within the web root as part of its propagation logic, ensuring maximum redundancy. The C2 server hosts a file called people2.txt containing 3,080 target IP addresses, representing the automated reconnaissance output used to feed new exploitation attempts.

How Does JOMANGY Malware Function?

JOMANGY's operation can be broken into three functional domains: evasion, persistence, and monetization.

Evasion

Every JOMANGY sample uses double-layer obfuscation. An outer Base64 encoding wraps a PHP string, which when decoded applies the ROT13 cipher to a second encoded layer before executing the result on the server. The threat actor actively rotates the payload contents between deployments, which produces distinct file hashes across samples and ensures near-zero antivirus detection rates at the time of initial deployment. The consistent internal watermark (trace_e1ebf9066a951be519a24140711839ea) is the forensic thread linking all variants to a common source despite the hash diversity.

Persistence (Six Independent Channels)

The six persistence mechanisms are designed so that any single surviving channel can fully rebuild the infection:

  • Cron-based C2 polling — A cron job polls the attacker's C2 server every one to three minutes, ready to receive new commands or re-download components.
  • Shell profile injection — Malicious code is injected into shell profile files, firing whenever root logs in or the system reboots.
  • Immutable crontab backups — Eight crontab backup copies are protected with chattr +i (making them undeletable without removing the immutable flag first), monitored by two dedicated restore cron loops that continuously verify and repair the others.
  • Process watchdog — A dedicated watchdog process monitors for the absence of the beacon process and immediately re-downloads the dropper if it disappears.
  • Immutable webshell copies — JOMANGY is replicated across more than twelve web root paths, many locked immutable, so that a single HTTP request to any surviving copy rebuilds the full infection stack.
  • Self-reinstalling PHP executor (license.php) — A PHP executor embedded within FreePBX's high-availability (HA) module provides privileged command execution independently of all other channels. It contains no authentication controls and relies on remotely supplied format-string placeholders before activation — making it a particularly dangerous backstop.

Monetization (Toll Fraud)

Every deployed JOMANGY instance carries active VoIP toll fraud code. Attackers use Asterisk CLI commands — such as asterisk -rx "channel originate Local/@" — to initiate outbound calls through the victim's own SIP trunks. These calls are routed to international premium-rate numbers (IPRNs) controlled by the attacker. The victim's telecom carrier charges the victim's account for all generated call volume. This method generates revenue with minimal operational overhead and leaves no ransomware artifacts for incident responders to follow.

How Businesses Can Use ANY.RUN’s Threat Intelligence Feeds and TI Lookup Against JOMANGY

Understanding a threat is only half the battle: organizations need actionable intelligence to defend against it proactively. ANY.RUN's Threat Intelligence Feeds and Threat Intelligence Lookup are purpose-built for exactly this kind of defense.

ANY.RUN Threat Intelligence Feeds deliver a continuously refreshed stream of high-confidence, machine-readable IOCs in formats compatible with SIEMs, firewalls, EDR platforms, and SOAR playbooks.

For a campaign like JOMANGY, where the attacker actively rotates payload hashes and migrates C2 infrastructure, having a real-time feed that captures fresh indicators as the campaign evolves is critical. Security teams can automatically block newly identified JOMANGY C2 addresses, flag access attempts to known malicious paths in the FreePBX web root, and alert on behavioral indicators such as the characteristic cron injection patterns used by the malware.

TI Feeds benefits and integration TI Feeds benefits and integration

ANY.RUN Threat Intelligence Lookup allows security teams to instantly query a continuously updated threat intelligence database for indicators of compromise (IOCs) directly associated with JOMANGY and the broader INJ3CTOR3 campaign.

Security analysts can search for known malicious IP addresses (including the 3,080-entry target inventory hosted on JOMANGY's C2), file hashes of JOMANGY and ZenharR samples, the campaign's unique watermark string (trace_e1ebf9066a951be519a24140711839ea), suspicious file paths dropped during infection, and known C2 domain and infrastructure details.

TI Lookup reveals two active JOMANGY infrastructure clusters tied to attacker-controlled C2 servers, with activity traced back to April 2026. This visibility helps threat hunters uncover related activity, identify compromised environments, and track infrastructure reuse across campaigns:

destinationIP:"160.119.69.4" OR destinationIP:"45.95.147.178".

JOMANGY infrastructure in TI Lookup JOMANGY infrastructure in TI Lookup

Organizations should also:

  • Patch FreePBX systems promptly;
  • Restrict internet exposure of management interfaces;
  • Monitor SIP activity for unusual call patterns;
  • Enable multi-factor authentication;
  • Audit privileged accounts regularly;
  • Monitor cron jobs and startup scripts;
  • Use EDR and server monitoring solutions;
  • Segment VoIP infrastructure from business-critical systems;
  • Rebuild compromised systems from clean images when infection is confirmed.

Researchers emphasize that partial cleanup may be ineffective due to JOMANGY's self-healing capabilities.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

JOMANGY represents a sophisticated evolution of VoIP-focused malware. While its primary objective is financial gain through toll fraud, its extensive persistence mechanisms, hidden accounts, and self-healing architecture make it a serious threat to organizations relying on FreePBX infrastructure.

For defenders, rapid visibility into malicious infrastructure, continuous threat intelligence, and proactive hunting are critical for detecting attacks before they result in substantial financial losses or long-term compromise. Combining strong patch management with threat intelligence-driven monitoring can significantly reduce exposure to emerging threats such as JOMANGY.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

BlackMatter screenshot
BlackMatter
blackmatter
BlackMatter is a ransomware strain operating as a Ransomware-as-a-Service (RaaS), designed to encrypt files, remove recovery options, and extort victims across critical industries. Emerging in 2021, it quickly became a major concern due to its ability to evade defenses, spread across networks, and cause large-scale operational disruption, forcing security teams to act against a highly destructive and persistent threat.
Read More
Loader screenshot
Loader
loader downloader
A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.
Read More
Sliver screenshot
Sliver
sliver
Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.
Read More
TrustConnect screenshot
TrustConnect
trustconnect
TrustConnect is a MaaS platform that disguises a Remote Access Trojan (RAT) as a legitimate Remote Monitoring and Management (RMM) tool. The operators built an AI-generated business website, obtained a fraudulently acquired Extended Validation (EV) code-signing certificate, and created fake customer statistics and documentation to make TrustConnect appear to the world — and to security tools — as a legitimate software company.
Read More
Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Rootkit screenshot
Rootkit
rootkit bootkit
A rootkit is a type of malicious software designed to provide unauthorized administrative-level access to a computer or network while concealing its presence. Rootkits are tools used by cybercriminals to hide their activities, including keyloggers, spyware, and other malware, often enabling long-term system exploitation.
Read More