EncystPHP Webshell Scans Signal Persistent FreePBX Compromise Attempts
Attackers are no longer just scanning FreePBX systems randomly; they are actively probing for a specific EncystPHP webshell that grants persistent backdoor access. This webshell uses a misleading 'md5' parameter that is actually a fixed string check, so detection methods relying on real MD5 hash validation or parameter name alone will miss these probes. The shift means defenders face not just opportunistic scans but targeted attempts to maintain durable control over VoIP infrastructure.
Recent scan activity matches the exact URL pattern Fortinet documented in January, confirming that attackers are hunting for this particular webshell on FreePBX hosts. Observed probes include commands to create or reset Linux accounts with known password hashes, indicating attackers aim to establish persistent footholds rather than just initial access. The scans originate from a Netherlands-based IP also linked to other FreePBX exploit attempts, underscoring an ongoing campaign targeting telecommunications systems.
This development raises the risk profile for FreePBX operators: the threat is not just intrusion but long-term compromise that can survive initial remediation efforts. Standard perimeter defenses and generic web scan alerts may understate the presence of this backdoor. While this is not an emergency patch situation, it demands active threat intelligence monitoring and validation of exposure to detect and respond to persistent EncystPHP webshell activity.