Hackers target flaws in PBX system to hijack VoIP calls

Flaws in Sangoma PBX allow hackers to make outgoing calls to premium-rate numbers

binary on a screen with words 'hacking attack'

Cyber criminals have launched a new campaign that targets Sangoma PBX, an open source web GUI that manages communications toolkit Asterisk, security researchers have said.

The attack exploits CVE-2019-19006, a critical vulnerability in Sangoma private branch exchange (PBX), which grants the attacker admin access to the system and gives them control over its functions.

Nearly 1,200 organisations worldwide over past 12 months are said to have been targeted, with the main purpose of the campaign being to lift phone numbers and gain live access to compromised VoIP services, according to a blog by researchers at Check Point Software.

Countries targeted include the Netherlands, Belgium, US, Columbia, and Germany. However, over half of the attacks so far have been aimed at companies based in the UK, in industries such as government, military, insurance, finance, and manufacturing.

“While investigating the exploitations, researchers identified several online profiles associated with private Facebook groups that deal with VoIP, and more specifically, SIP server exploitation," said researchers Ido Solomon, Ori Hamama and Omer Ventura, in a joint blog post. 

They added that investigations into the source of the attacks suggested that most hackers were based in Gaza, the West Bank, and Egypt.

It was also concluded that the group has mostly tried to gain access to phone numbers, and sell these on to other groups, and grant access to compromised VoIP services “to the highest bidders, who can then exploit those services for their own purposes”.

Related Resource

Adding cloud telephony to Microsoft Teams

Collaboration technology for flexible working

Download now

Researchers said that hackers could also use the compromised systems to support further attacks, such as using the system resources for cryptocurrency mining, spreading laterally across the company network, or launching attacks on outside targets, while masquerading as representatives from the compromised company.

Companies using vulnerable systems have been urged to change all default passwords and analyse call billings on a regular basis as well as applying patches to close the CVE-2019-19006 vulnerability that hackers are exploiting. 

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

SonicWall hacked via zero-day flaw in remote access tools
Security

SonicWall hacked via zero-day flaw in remote access tools

25 Jan 2021
Global ransom DDoS extortionists are retargeting companies
distributed denial of service (DDOS)

Global ransom DDoS extortionists are retargeting companies

22 Jan 2021
Best ransomware removal tools
ransomware

Best ransomware removal tools

22 Jan 2021
Hackers publish over 4,000 files stolen from SEPA in ransomware attack
Security

Hackers publish over 4,000 files stolen from SEPA in ransomware attack

22 Jan 2021

Most Popular

How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
WhatsApp could face €50 million GDPR fine
General Data Protection Regulation (GDPR)

WhatsApp could face €50 million GDPR fine

25 Jan 2021
Trump pardons convicted ex-Google engineer Levandowski
intellectual property

Trump pardons convicted ex-Google engineer Levandowski

20 Jan 2021