Nahda is a criminal threat actor associated with compromises of internet-exposed FreePBX and related VoIP platforms. The actor is identified in intrusion-cleanup logic used by a competing VoIP fraud operation, which explicitly removed Nahda-associated user accounts and artifacts from infected systems, indicating Nahda was one of several groups competing for persistent control of vulnerable PBX environments. Known associated account names include nahda and FreePBX_setup. Nahda is linked to activity in the VoIP fraud ecosystem, particularly operations that abuse compromised telephony infrastructure for unauthorized call origination and related toll-fraud schemes. The actor’s tradecraft, as evidenced by rival-removal behavior targeting its implants, indicates use of persistence on compromised PBX hosts through local account creation and likely web-based access mechanisms common to FreePBX intrusions. Nahda appears to operate as part of a broader cluster of criminal actors targeting FreePBX, Elastix, Issabel, and Sangoma systems for exclusive access to SIP trunks and administrative control. The name Nahda is Arabic for “renaissance,” and the observed naming conventions suggest a possible Middle Eastern nexus; however, this attribution is not established at high confidence. No specific country of origin can be confirmed from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.