INJ3CTOR3
- First seen
- 2020-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:24:13
Targeted industries: technology-and-telecommunications
Context
INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Their operations involve exploiting FreePBX vulnerabilities to deploy PHP web shells for data exfiltration and persistence. The group utilizes tools for SIP server exploitation, including brute-force scripts and authentication bypass techniques. Observations indicate a resurgence of their attack patterns, reflecting historical behaviors while adapting to current vulnerabilities.
Exploited vulnerabilities
- CVE-2019-19006 (vulnerability)
- CVE-2021-45461 (vulnerability)
Reports & references
- research.checkpoint.com — Inj3Ctor3 Operation Leveraging Asterisk Servers For Monetization (report)
- Palo Alto Unit 42 — Digium Phones Web Shell (report)
- fortinet.com — Unveiling The Weaponized Web Shell Encystphp (report)