Executive SummaryRisk level: High
What happened

Since December 2025, attackers have exploited a command-injection vulnerability in Sangoma FreePBX to deploy web shells on 900+ instances worldwide (US, Brazil, Canada, Germany, France), gaining persistent remote access.

Who is affected

Organizations running internet-exposed Sangoma FreePBX communication systems.

Why it matters

Web shells provide durable backdoors for remote command execution and lateral movement, threatening operational integrity.

Immediate recommended actions

  • Patch FreePBX and reduce internet exposure of the management interface.
  • Scan web directories for unexpected scripts/web shells (FIM).
  • Hunt for the application spawning shells and anomalous outbound traffic.
  • Segment FreePBX from sensitive internal networks.
How to read this report. Items are labelled by confidence: Confirmed stated as fact in the source, Reported described by the source, Potential analyst inference, and Requires Validation to be confirmed in your environment. Where the source lacks detail this is stated as “Not specified in the source material”.

Key Technical Findings

Vulnerability / Campaign Type

Command-injection exploitation deploying web shells on Sangoma FreePBX.

Affected Systems

900+ internet-exposed FreePBX instances globally.

Initial Access Vector

Crafted HTTP requests exploiting the command-injection flaw.

Execution Method

Web shells deployed for remote command execution (T1203).

Persistence

Web shells provide a durable backdoor (T1505).

Privilege Escalation

Attempts to gain higher privileges after access.

Defense Evasion

Obfuscation to hide malicious activity.

Credential Access

Not specified in the source material.

Lateral Movement

Exploiting trust relationships to spread.

Data Exfiltration

Unusual outbound transfers to unknown IPs.

Impact Level

High – persistent server compromise via web shells.

Technical Background

The command-injection flaw lets attackers run arbitrary commands by crafting specific HTTP requests, which they use to install web shells (T1203/T1505). The web shell then serves as a persistent backdoor enabling remote command execution and lateral movement.

Because FreePBX is often internet-facing, defenses center on patching, exposure reduction, file-integrity monitoring of web directories, and detecting the application spawning shells or making anomalous outbound connections.

Attack Chain Analysis

  1. Initial Access

    ActivityExploit command injection via crafted HTTP requests.

    EvidenceAnomalous requests to FreePBX.

    TelemetryWeb access/error logs, WAF.

    Detection opportunityAlert on requests with command metacharacters.

  2. Execution

    ActivityDeploy and run web shells (T1203).

    EvidenceNew server-side scripts; app spawning shells.

    TelemetryFIM, EDR, web logs.

    Detection opportunityDetect web shells and shell spawning.

  3. Persistence

    ActivityMaintain access via web shell (T1505).

    EvidenceRecurring access to the web shell file.

    TelemetryWeb access logs.

    Detection opportunityMonitor access to suspicious scripts.

  4. Lateral Movement

    ActivitySpread via trust relationships.

    EvidenceUnexpected internal connections.

    TelemetryNetflow, firewall.

    Detection opportunityFlag new internal flows from FreePBX.

Deep Technical Behavior Analysis

The defining behaviors are web-shell deployment in writable web paths and subsequent anomalous POSTs/outbound connections. File-integrity monitoring and detection of the application process spawning shells provide the highest-fidelity signals.

Specific web-shell file names, hashes, and C2 IPs are not specified in the source material and require validation.

Indicators of Compromise

No indicators of compromise were provided in the source material.

Indicators of Behavior

Behavioral indicators to hunt for even when atomic IoCs are limited (Potential — validate against your baseline).

Behavioral Indicator Description Data Source Confidence
Anomalous PowerShell execution Encoded/obfuscated commands, download cradles, or unusual parent-child process lineage. Sysmon EID 1, PowerShell 4104 Potential
Suspicious child process lineage Office or web/service processes spawning script hosts or shells. Sysmon EID 1, EDR Potential
Security log clearing Event log cleared or audit policy changed to hinder visibility. Windows Security 1102, 4719 Potential
New service / scheduled task creation Unexpected persistence via services or tasks. Security 7045, 4698; Sysmon Potential
New SSH authorized_keys / cron entries Unexpected persistence on Linux hosts. auditd, /var/log/secure, cron logs Potential
Shell history gaps or clearing History truncated or redirected to /dev/null. auditd, bash history Potential
Web shell-like activity New/modified server-side scripts in writable web paths; anomalous POSTs. Web access/error logs, FIM Potential
Abnormal 403/404/500 patterns Enumeration or exploitation attempts against endpoints. Web server logs, WAF Potential
Beaconing to rare destinations Periodic outbound connections to newly-seen domains/IPs or direct-IP C2. Proxy, firewall, DNS logs Potential
Unusual DNS queries High-entropy or rare domains; possible tunneling. DNS resolver logs Potential

Detection Engineering Guidance

Defensive detection logic (Potential — tune to your environment). No exploit code is included; logic is for hunting and alerting only.

Baseline detection guidance
  • ObjectiveSurface anomalous process, persistence, and outbound activity.
  • Data sourceEDR, Sysmon, authentication and proxy/DNS logs.
  • ResponseTriage, validate, preserve evidence, contain if confirmed.
Platform Log Source What to Look For Priority
Windows Security Event Log Logon (4624/4625), service (7045), task (4698), log clear (1102) High
Windows Sysmon Process creation (1), network (3), image load (7), LSASS access (10) High
Windows PowerShell Operational Script block logging (4104), module logging High
Endpoint EDR / Defender telemetry Process tree, persistence, tamper attempts High
Web Web server access logs Anomalous POSTs, new endpoints, web-shell-like requests High
Web Web server error logs Repeated 403/404/500 bursts on single endpoints Medium
Linux auth.log / secure SSH logins, sudo, account changes High
Linux auditd execve, file writes, persistence paths High
Network DNS resolver logs Rare/high-entropy domains, tunneling Medium
Network Proxy / firewall logs Beaconing, direct-IP C2, exfil volume High

MITRE ATT&CK Mapping

Tactic Technique ID Technique Name Relevance Detection Opportunity Confidence
Execution T1203 Exploitation for Client Execution Exploiting vulnerabilities in client applications to execute commands. Monitoring for unusual application behavior and traffic anomalies. Reported
Execution T1505 Server Software Component Exploiting server components to execute unauthorized commands. Log analysis for unauthorized execution attempts. Reported

Incident Response Guidance

  • Validate exposure and confirm whether the issue applies to your environment.
  • Preserve evidence (memory, disk, relevant logs) before remediation.
  • Isolate affected hosts/accounts if compromise is suspected.
  • Collect volatile data and review the log sources listed above.
  • Hunt for the indicators of behavior and any related atomic indicators.
  • Rotate potentially exposed credentials, keys, and session tokens.
  • Remove persistence (tasks, services, keys, web shells, cron, OAuth grants).
  • Patch affected systems; reimage where integrity cannot be assured.
  • Run post-remediation validation and a BAS/security-validation retest.

Remediation and Hardening

  • Patch affected systems and reduce internet-exposed services.
  • Enforce MFA and least-privilege for privileged and remote access.
  • Improve endpoint telemetry (Sysmon/EDR) and PowerShell logging.
  • Restrict script execution and constrain LOLBins where feasible.
  • Monitor persistence locations and disable unnecessary services.
  • Segment critical assets and review privileged accounts.
  • Rotate secrets and remove credentials from configuration files.
  • Tune SIEM/EDR detections, then validate controls after changes.

Business Risk

  • Service disruption: degraded or unavailable systems during compromise or recovery.
  • Data exposure: risk to sensitive, regulated, or customer data depending on scope.
  • Regulatory exposure: potential breach-notification and compliance obligations.
  • Financial impact: incident response, downtime, and potential extortion costs.
  • Brand and trust impact: reputational damage with customers and partners.

Executive Takeaway

What leadership needs to know: Web shells provide durable backdoors for remote command execution and lateral movement, threatening operational integrity. Current assessed risk: High.

Prioritise: patching/exposure reduction, identity hardening (MFA, least privilege), and detection coverage for the techniques above.

Validate after remediation: re-test controls with breach & attack simulation to confirm the relevant techniques are now prevented or detected.

Validating Your Defenses with Valitrix

A proactive approach to cybersecurity involves continuously validating security measures against real-world adversary techniques. The Valitrix Breach and Attack Simulation (BAS) platform offers an effective means to test defenses against specific MITRE ATT&CK techniques relevant to web shell attacks. By simulating these attack vectors safely, organizations can identify gaps in their security posture and strengthen their defenses accordingly.

The Valitrix platform enables organizations to automate testing against known vulnerabilities, ensuring that detection and prevention controls are functioning as intended. This continual validation process is vital in adapting to evolving threats and maintaining resilience against cyber attacks.

Key Takeaways

  • Over 900 Sangoma FreePBX instances have been compromised due to web shell attacks exploiting command injection vulnerabilities.
  • The attack chain includes initial access, execution, persistence, and lateral movement tactics.
  • Organizations should monitor for specific IOCs such as unexpected web shell files and unusual outbound traffic.
  • Regular updates and security audits are crucial defenses against these attacks.

Frequently Asked Questions

What is Sangoma FreePBX?

Sangoma FreePBX is an open-source communications platform used extensively for managing telephony systems in businesses.

How can I detect if my FreePBX instance has been compromised?

Look for indicators such as unexpected files in web directories, unusual outbound traffic patterns, and log anomalies indicating unauthorized command executions.

What should I do if I find a web shell on my server?

If a web shell is detected, immediately isolate the affected system, perform a thorough investigation to assess the impact, and remove any malicious files found.