inj3ct0r is a financially motivated threat actor associated with attacks against internet-exposed VoIP and SIP infrastructure, particularly Sangoma FreePBX and Asterisk environments. The actor has been linked to the online personas INJ3CTOR3 and Inj3ct0r3-Seraj. Activity attributed to this actor centers on compromising vulnerable PBX systems and monetizing access by abusing outbound calling capabilities, including use of compromised telephony infrastructure for revenue-generating call fraud. The actor has been observed exploiting CVE-2019-19006, an authentication bypass in vulnerable FreePBX Framework versions, to obtain administrative sessions without valid credentials. Operations include internet-wide reconnaissance and scanning for exposed SIP services, followed by exploitation, deployment of PHP web shells, credential harvesting from Asterisk and FreePBX configuration data, and installation of a web-based panel used to place calls through compromised systems. Post-compromise behavior has included modifying server-side configuration to preserve access paths, creating attacker-controlled directories, and attempting to update the vulnerable framework, likely to stabilize or retain exclusive access after compromise. Tooling and tradecraft associated with inj3ct0r include use of SIPVicious for target discovery, command execution through Asterisk-related functionality, password-protected web shells, source-restricted access controls, and collection of PBX, database, SIP extension, and related service credentials. The actor’s tooling has also supported arbitrary command execution and management of call operations across compromised FreePBX and Elastix systems. Publicly exposed scripts and persona overlaps connect the actor to a broader VoIP exploitation ecosystem active in the Middle East, where compromised SIP infrastructure and call capacity are traded and abused for telephony fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.