Since December 2025, attackers have exploited a command-injection vulnerability in Sangoma FreePBX to deploy web shells on 900+ instances worldwide (US, Brazil, Canada, Germany, France), gaining persistent remote access.
Organizations running internet-exposed Sangoma FreePBX communication systems.
Web shells provide durable backdoors for remote command execution and lateral movement, threatening operational integrity.
- Patch FreePBX and reduce internet exposure of the management interface.
- Scan web directories for unexpected scripts/web shells (FIM).
- Hunt for the application spawning shells and anomalous outbound traffic.
- Segment FreePBX from sensitive internal networks.
Key Technical Findings
Command-injection exploitation deploying web shells on Sangoma FreePBX.
900+ internet-exposed FreePBX instances globally.
Crafted HTTP requests exploiting the command-injection flaw.
Web shells deployed for remote command execution (T1203).
Web shells provide a durable backdoor (T1505).
Attempts to gain higher privileges after access.
Obfuscation to hide malicious activity.
Not specified in the source material.
Exploiting trust relationships to spread.
Unusual outbound transfers to unknown IPs.
High – persistent server compromise via web shells.
Technical Background
The command-injection flaw lets attackers run arbitrary commands by crafting specific HTTP requests, which they use to install web shells (T1203/T1505). The web shell then serves as a persistent backdoor enabling remote command execution and lateral movement.
Because FreePBX is often internet-facing, defenses center on patching, exposure reduction, file-integrity monitoring of web directories, and detecting the application spawning shells or making anomalous outbound connections.
Attack Chain Analysis
-
Initial Access
ActivityExploit command injection via crafted HTTP requests.
EvidenceAnomalous requests to FreePBX.
TelemetryWeb access/error logs, WAF.
Detection opportunityAlert on requests with command metacharacters.
-
Execution
ActivityDeploy and run web shells (T1203).
EvidenceNew server-side scripts; app spawning shells.
TelemetryFIM, EDR, web logs.
Detection opportunityDetect web shells and shell spawning.
-
Persistence
ActivityMaintain access via web shell (T1505).
EvidenceRecurring access to the web shell file.
TelemetryWeb access logs.
Detection opportunityMonitor access to suspicious scripts.
-
Lateral Movement
ActivitySpread via trust relationships.
EvidenceUnexpected internal connections.
TelemetryNetflow, firewall.
Detection opportunityFlag new internal flows from FreePBX.
Deep Technical Behavior Analysis
The defining behaviors are web-shell deployment in writable web paths and subsequent anomalous POSTs/outbound connections. File-integrity monitoring and detection of the application process spawning shells provide the highest-fidelity signals.
Specific web-shell file names, hashes, and C2 IPs are not specified in the source material and require validation.
Indicators of Compromise
Indicators of Behavior
Behavioral indicators to hunt for even when atomic IoCs are limited (Potential — validate against your baseline).
| Behavioral Indicator | Description | Data Source | Confidence |
|---|---|---|---|
| Anomalous PowerShell execution | Encoded/obfuscated commands, download cradles, or unusual parent-child process lineage. | Sysmon EID 1, PowerShell 4104 | Potential |
| Suspicious child process lineage | Office or web/service processes spawning script hosts or shells. | Sysmon EID 1, EDR | Potential |
| Security log clearing | Event log cleared or audit policy changed to hinder visibility. | Windows Security 1102, 4719 | Potential |
| New service / scheduled task creation | Unexpected persistence via services or tasks. | Security 7045, 4698; Sysmon | Potential |
| New SSH authorized_keys / cron entries | Unexpected persistence on Linux hosts. | auditd, /var/log/secure, cron logs | Potential |
| Shell history gaps or clearing | History truncated or redirected to /dev/null. | auditd, bash history | Potential |
| Web shell-like activity | New/modified server-side scripts in writable web paths; anomalous POSTs. | Web access/error logs, FIM | Potential |
| Abnormal 403/404/500 patterns | Enumeration or exploitation attempts against endpoints. | Web server logs, WAF | Potential |
| Beaconing to rare destinations | Periodic outbound connections to newly-seen domains/IPs or direct-IP C2. | Proxy, firewall, DNS logs | Potential |
| Unusual DNS queries | High-entropy or rare domains; possible tunneling. | DNS resolver logs | Potential |
Detection Engineering Guidance
Defensive detection logic (Potential — tune to your environment). No exploit code is included; logic is for hunting and alerting only.
Recommended Log Sources
| Platform | Log Source | What to Look For | Priority |
|---|---|---|---|
| Windows | Security Event Log | Logon (4624/4625), service (7045), task (4698), log clear (1102) | High |
| Windows | Sysmon | Process creation (1), network (3), image load (7), LSASS access (10) | High |
| Windows | PowerShell Operational | Script block logging (4104), module logging | High |
| Endpoint | EDR / Defender telemetry | Process tree, persistence, tamper attempts | High |
| Web | Web server access logs | Anomalous POSTs, new endpoints, web-shell-like requests | High |
| Web | Web server error logs | Repeated 403/404/500 bursts on single endpoints | Medium |
| Linux | auth.log / secure | SSH logins, sudo, account changes | High |
| Linux | auditd | execve, file writes, persistence paths | High |
| Network | DNS resolver logs | Rare/high-entropy domains, tunneling | Medium |
| Network | Proxy / firewall logs | Beaconing, direct-IP C2, exfil volume | High |
MITRE ATT&CK Mapping
| Tactic | Technique ID | Technique Name | Relevance | Detection Opportunity | Confidence |
|---|---|---|---|---|---|
| Execution | T1203 | Exploitation for Client Execution | Exploiting vulnerabilities in client applications to execute commands. | Monitoring for unusual application behavior and traffic anomalies. | Reported |
| Execution | T1505 | Server Software Component | Exploiting server components to execute unauthorized commands. | Log analysis for unauthorized execution attempts. | Reported |
Incident Response Guidance
- Validate exposure and confirm whether the issue applies to your environment.
- Preserve evidence (memory, disk, relevant logs) before remediation.
- Isolate affected hosts/accounts if compromise is suspected.
- Collect volatile data and review the log sources listed above.
- Hunt for the indicators of behavior and any related atomic indicators.
- Rotate potentially exposed credentials, keys, and session tokens.
- Remove persistence (tasks, services, keys, web shells, cron, OAuth grants).
- Patch affected systems; reimage where integrity cannot be assured.
- Run post-remediation validation and a BAS/security-validation retest.
Remediation and Hardening
- Patch affected systems and reduce internet-exposed services.
- Enforce MFA and least-privilege for privileged and remote access.
- Improve endpoint telemetry (Sysmon/EDR) and PowerShell logging.
- Restrict script execution and constrain LOLBins where feasible.
- Monitor persistence locations and disable unnecessary services.
- Segment critical assets and review privileged accounts.
- Rotate secrets and remove credentials from configuration files.
- Tune SIEM/EDR detections, then validate controls after changes.
Business Risk
- Service disruption: degraded or unavailable systems during compromise or recovery.
- Data exposure: risk to sensitive, regulated, or customer data depending on scope.
- Regulatory exposure: potential breach-notification and compliance obligations.
- Financial impact: incident response, downtime, and potential extortion costs.
- Brand and trust impact: reputational damage with customers and partners.
Executive Takeaway
What leadership needs to know: Web shells provide durable backdoors for remote command execution and lateral movement, threatening operational integrity. Current assessed risk: High.
Prioritise: patching/exposure reduction, identity hardening (MFA, least privilege), and detection coverage for the techniques above.
Validate after remediation: re-test controls with breach & attack simulation to confirm the relevant techniques are now prevented or detected.
Validating Your Defenses with Valitrix
A proactive approach to cybersecurity involves continuously validating security measures against real-world adversary techniques. The Valitrix Breach and Attack Simulation (BAS) platform offers an effective means to test defenses against specific MITRE ATT&CK techniques relevant to web shell attacks. By simulating these attack vectors safely, organizations can identify gaps in their security posture and strengthen their defenses accordingly.
The Valitrix platform enables organizations to automate testing against known vulnerabilities, ensuring that detection and prevention controls are functioning as intended. This continual validation process is vital in adapting to evolving threats and maintaining resilience against cyber attacks.
Key Takeaways
- Over 900 Sangoma FreePBX instances have been compromised due to web shell attacks exploiting command injection vulnerabilities.
- The attack chain includes initial access, execution, persistence, and lateral movement tactics.
- Organizations should monitor for specific IOCs such as unexpected web shell files and unusual outbound traffic.
- Regular updates and security audits are crucial defenses against these attacks.
Frequently Asked Questions
What is Sangoma FreePBX?
Sangoma FreePBX is an open-source communications platform used extensively for managing telephony systems in businesses.
How can I detect if my FreePBX instance has been compromised?
Look for indicators such as unexpected files in web directories, unusual outbound traffic patterns, and log anomalies indicating unauthorized command executions.
What should I do if I find a web shell on my server?
If a web shell is detected, immediately isolate the affected system, perform a thorough investigation to assess the impact, and remove any malicious files found.



