INJ3CTOR3

First seen
2020-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:24:13

Targeted industries: technology-and-telecommunications

Context

INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Their operations involve exploiting FreePBX vulnerabilities to deploy PHP web shells for data exfiltration and persistence. The group utilizes tools for SIP server exploitation, including brute-force scripts and authentication bypass techniques. Observations indicate a resurgence of their attack patterns, reflecting historical behaviors while adapting to current vulnerabilities.

Exploited vulnerabilities

  • CVE-2019-19006 (vulnerability)
  • CVE-2021-45461 (vulnerability)

Reports & references

  • research.checkpoint.com — Inj3Ctor3 Operation Leveraging Asterisk Servers For Monetization (report)
  • Palo Alto Unit 42 — Digium Phones Web Shell (report)
  • fortinet.com — Unveiling The Weaponized Web Shell Encystphp (report)

External references