Hackers target flaws in PBX system to hijack VoIP calls

Flaws in Sangoma PBX allow hackers to make outgoing calls to premium-rate numbers

binary on a screen with words 'hacking attack'

Cyber criminals have launched a new campaign that targets Sangoma PBX, an open source web GUI that manages communications toolkit Asterisk, security researchers have said.

The attack exploits CVE-2019-19006, a critical vulnerability in Sangoma private branch exchange (PBX), which grants the attacker admin access to the system and gives them control over its functions.

Nearly 1,200 organisations worldwide over past 12 months are said to have been targeted, with the main purpose of the campaign being to lift phone numbers and gain live access to compromised VoIP services, according to a blog by researchers at Check Point Software.

Countries targeted include the Netherlands, Belgium, US, Columbia, and Germany. However, over half of the attacks so far have been aimed at companies based in the UK, in industries such as government, military, insurance, finance, and manufacturing.

“While investigating the exploitations, researchers identified several online profiles associated with private Facebook groups that deal with VoIP, and more specifically, SIP server exploitation," said researchers Ido Solomon, Ori Hamama and Omer Ventura, in a joint blog post. 

They added that investigations into the source of the attacks suggested that most hackers were based in Gaza, the West Bank, and Egypt.

It was also concluded that the group has mostly tried to gain access to phone numbers, and sell these on to other groups, and grant access to compromised VoIP services “to the highest bidders, who can then exploit those services for their own purposes”.

Related Resource

Adding cloud telephony to Microsoft Teams

Collaboration technology for flexible working

Download now

Researchers said that hackers could also use the compromised systems to support further attacks, such as using the system resources for cryptocurrency mining, spreading laterally across the company network, or launching attacks on outside targets, while masquerading as representatives from the compromised company.

Companies using vulnerable systems have been urged to change all default passwords and analyse call billings on a regular basis as well as applying patches to close the CVE-2019-19006 vulnerability that hackers are exploiting. 

Featured Resources

2021 Thales cloud security study

The challenges of cloud data protection and access management in a hybrid and multi cloud world

Free download

IDC agility assessment

The competitive advantage in adaptability

Free Download

Digital transformation insights from CIOs for CIOs

Transformation pilotes, co-pilots, and engineers

Free download

What ITDMs did next - and what they should be doing now

Enable continued collaboration and communication for hybrid workers

Recommended

US government warns of increased risk of ransomware over holiday season
ransomware

US government warns of increased risk of ransomware over holiday season

24 Nov 2021
Hackers use Linux backdoor on compromised e-commerce sites with software skimmer
malware

Hackers use Linux backdoor on compromised e-commerce sites with software skimmer

19 Nov 2021
Iranian hackers ramp up attacks against IT services sector
hacking

Iranian hackers ramp up attacks against IT services sector

19 Nov 2021
TikTok phishing campaign tried to scam over 125 influencer accounts
social media

TikTok phishing campaign tried to scam over 125 influencer accounts

18 Nov 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

30 Nov 2021
Microsoft seizes domains used by Chinese hacking group
cyber attacks

Microsoft seizes domains used by Chinese hacking group

7 Dec 2021
What is single sign-on (SSO)?
single sign-on (SSO)

What is single sign-on (SSO)?

2 Dec 2021