Threat analysts have discovered a large-scale campaign targeting Elastix VoIP telephony servers with more than 500,000 malware samples over a three-month period.
See also: App Store: 84 scammy apps secretly charge iPhone users

Elastix is a server software for unified communications (Internet Protocol Private Branch Exchange [IP PBX], email, instant messaging, fax) used in the Digium telephone module for FreePBX.
Attackers may have exploited a remote code execution (RCE) vulnerability identified as CVE-2021-45461, with a critical severity rating of 9.8 out of 10.
Hackers have been exploiting this vulnerability since December 2021, and the recent campaign appears to be linked to the security.
Security researchers at Palo Alto Networks' Unit 42 say the attackers was to install a PHP web shell that could execute arbitrary commands on the compromised communications server.
See also: Mantis botnet behind record-breaking DDoS attack in June
In a report on Friday, researchers say the threat actor deployed “more than 500,000 unique malware samples of this family” between December 2021 and March 2022.
The campaign is still active and shares several similarities with another 2020 operation reported by researchers at cybersecurity firm Check Point.
Details of the attack
Researchers observed two attack groups using different initial exploitation scripts to drop a small shell script. The script installs a PHP backdoor on the targeted device and also creates root user and ensures persistence via scheduled tasks.
The IP addresses of the attackers from both groups are located in the Netherlands, while DNS records reveal links to several Russian adult websites. Currently, parts of the payload remain online and operational.
The scheduled task created by the first script runs every minute to retrieve a base64-encoded PHP web shell that can handle the following parameters in incoming web requests:
- md5 – MD5 authentication hash for remote login and web shell interaction.
- admin – Choose between Elastic and Freepbx administrator sessions.
- cmd – Execute arbitrary commands remotely
- call – Initiate a call from the Asterisk command line interface (CLI)

The web shell also has an additional set of eight built-in commands for reading files, directory listing, and identifying the open source Asterisk PBX platform.
See also: Amazon admitted to providing Ring videos to authorities without owners' knowledge
The report from Unit42 includes technical details on how the payloads are dropped and some tactics to avoid detection in the existing environment. In addition, a list of indicators reveals local file paths used by the malware, unique strings, hashes for shell scripts , and public URLs hosting the payloads.
Information source: bleepingcomputer.com
