In the last year, a malicious campaign has compromised the VoIP (Voice over Internet Protocol) telephone systems of more than 1,000 companies around the world.

Although the main purpose of this attack is to sell phone numbers and calling plans that others can use for free, access to VoIP systems could provide criminals with the ability to carry out other attacks, including listening to private calls, cryptomining , or even using compromised systems as a starting stage for very serious attacks.
According to researchers at Check Point , a hacking group has compromised the VoIP networks of nearly 1,200 organizations in more than 20 countries, with over half of the victims located in the United Kingdom . Industries such as government, military, insurance, finance, and construction are believed to have fallen victim to the campaign.
Outside the United Kingdom, other countries such as the Netherlands, Belgium, the United States, Colombia and Germany have also been targeted by similar campaigns.
The attacks exploit CVE-2019-19006 , a critical vulnerability in the Sangoma and Asterisk VoIP phone systems that allows third parties to gain remote access without any form of authentication. A security update was released last year that fixes the vulnerability, but many organizations have yet to implement it, leaving cybercriminals to continue exploiting it.

"The vulnerability is an authentication bypass flaw, and the exploit is publicly available. Once exploited, hackers have administrator access to the VoIP system, which allows them to control its operations. This will not be detected unless an IT team specifically looks for it," Derek Middlemiss, a security researcher at Check Point Research, told ZDNet.
One of the most common reasons compromised systems are exploited is to make outbound calls without the VoIP system being aware, which would allow attackers to secretly call premium numbers they have created in order to bill the organization they have hacked. And because businesses make a lot of legitimate phone calls to these systems, it would be difficult to detect if a server.
Organizations are advised to change default usernames and passwords on devicesso that they cannot be easily exploited and, if possible, regularly analyze call charges for potentially suspicious destinations, traffic volume, or call patterns. Most importantly, organizations should apply required security updates to prevent the exploitation of known vulnerabilities.
