tchtowr is a criminal threat actor handle associated with compromises of internet-exposed VoIP platforms, particularly FreePBX-family environments. The actor is identified as one of several competing operations that implant and maintain unauthorized access on vulnerable PBX systems in order to monetize them through toll-fraud activity, especially International Revenue Share Fraud. Activity linked to this ecosystem shows operators seeking exclusive control of compromised telephony infrastructure and removing rival actors' implants, accounts, persistence mechanisms, and webshells. The broader intrusion pattern affecting this ecosystem includes exploitation of the FreePBX restapps REST API for remote code execution on unpatched systems, deployment of PHP webshells, establishment of durable persistence, log scrubbing, timestomping, creation of privileged operating-system and application backdoor accounts, SSH persistence, and abuse of SIP and Asterisk functionality to originate fraudulent calls. Artifacts associated with tchtowr were specifically targeted for removal by a competing VoIP-focused malware operation, indicating that tchtowr maintained recognizable implants or access mechanisms on compromised PBX hosts. Available information supports classifying tchtowr as part of a cluster of financially motivated VoIP fraud actors rather than a nation-state operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.