VictamPbx is a criminal VoIP-focused intrusion set associated with the compromise of internet-exposed FreePBX, Elastix, Issabel, and Sangoma systems for toll fraud, particularly International Revenue Share Fraud. The actor deploys a PHP webshell and related multi-stage malware to obtain and retain exclusive control of vulnerable PBX environments, abuse victim SIP trunks, and originate fraudulent calls through attacker-controlled telephony infrastructure. Operator branding observed in the intrusion set includes VictamPbx, emoadmin, emo, and Raza Telefonia. The actor has used the FreePBX restapps REST API as an initial remote code execution vector on unpatched systems. Its tooling establishes layered persistence through webshell deployment across multiple web-accessible paths, cron-based reinstallation, boot and login execution, creation of FreePBX administrator backdoors, addition of multiple root-equivalent operating-system accounts, and SSH key implantation. Defense-evasion measures include timestomping deployed files, scrubbing web logs, disabling defensive or competing PBX modules, and obfuscating webshell code. VictamPbx demonstrates notable post-compromise tradecraft aimed at monopolizing access to infected PBX servers. A later-stage payload systematically searches for and removes implants, accounts, cron jobs, and webshells associated with rival VoIP fraud actors, including Juba VoIP, Nahda, Badr or b3d0r, nvd0rz, tchTowr, and yokyok. This behavior indicates deliberate territorial competition among criminal groups seeking exclusive use of compromised telephony infrastructure. Observed capabilities include command execution, theft of Elastix credentials from local databases, hijacking of FreePBX administrative sessions, and abuse of Asterisk call origination features for fraudulent calling. The actor’s activity is consistent with financially motivated cybercrime rather than espionage or disruptive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.