Badr, also referenced as b3d0r, is a criminal threat actor associated with compromises of internet-exposed FreePBX and related VoIP platforms. The actor is identified through signature strings embedded in webshells and malware artifacts, indicating either a single operator using both names or closely related tooling variants. Badr appears in the ecosystem of competing groups that target PBX environments for illicit monetization, particularly toll-fraud activity involving unauthorized use of victim telephony infrastructure. The actor’s activity is linked to webshell deployment on VoIP systems and post-compromise persistence within FreePBX environments. Badr-associated artifacts were significant enough to be explicitly searched for and removed by a rival malware operation designed to evict competing access from compromised PBX servers. This indicates that Badr operates in the same contested criminal space as other VoIP-focused intrusion sets targeting FreePBX, Elastix, Issabel, and Sangoma deployments. Based on the available evidence, Badr is best characterized as a financially motivated cybercriminal actor focused on unauthorized access to PBX infrastructure, persistence on compromised systems, and post-exploitation abuse of telephony services. High-confidence reporting directly supports association with webshell-based access and broader VoIP fraud operations, but does not provide sufficient corroborated detail to attribute a specific national origin or enumerate a fuller independent intrusion lifecycle beyond the actor’s presence in compromised FreePBX environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.