216.73.217.22

Unveiling the Weaponized Web Shell EncystPHP

· Published 28/01/2026 18:26 · Modified 28/01/2026 22:47

Export JSON

Essential information

Published
28/01/2026 18:26
Modified
28/01/2026 22:47
Tags
2026-01-28 CVE-2025-64328 command injection encystphp evasion freepbx persistence telephony web shell
Related entities
3 vulnerabilities (cve), 5 observables, 1 intrusion sets (apt), 15 techniques (mitre), 1 malware, 5 others

Description

A sophisticated named has been discovered, targeting systems through the vulnerability. Associated with the hacker group INJ3CTOR3, this malware exhibits advanced capabilities including remote command execution, mechanisms, and deployment. The attack originated from Brazil, targeting an Indian technology company. employs various techniques to maintain , including creating cron jobs, injecting SSH keys, and deploying multiple instances of itself. It also attempts to evade detection by deleting logs and masquerading as legitimate files. The malware's impact includes full system compromise, unauthorized administrative access, and potential abuse of resources. Organizations are advised to treat any successful exploitation as a critical incident requiring immediate remediation and security hardening.

External references