{"id":41528,"date":"2020-11-06T12:15:46","date_gmt":"2020-11-06T12:15:46","guid":{"rendered":"http:\/\/icloud.pe\/blog\/?guid=b3a2c375a45f2e0ea9e6fcbf258e6e20"},"modified":"2020-11-06T12:15:46","modified_gmt":"2020-11-06T12:15:46","slug":"hackers-target-flaws-in-pbx-system-to-hijack-voip-calls","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/hackers-target-flaws-in-pbx-system-to-hijack-voip-calls\/","title":{"rendered":"Hackers target flaws in PBX system to hijack VoIP calls"},"content":{"rendered":"<p><span class=\"field field-name-field-author field-type-node-reference field-label-hidden\"><br \/>\n      <span class=\"field-item even\"><a href=\"https:\/\/www.cloudpro.co.uk\/authors\/rene-millman\">Rene Millman<\/a><\/span><br \/>\n  <\/span><\/p>\n<div class=\"field field-name-field-published-date field-type-datetime field-label-hidden\">\n<div class=\"field-items\">\n<div class=\"field-item even\"><span class=\"date-display-single\">6 Nov, 2020<\/span><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"short-teaser\">\n<a href=\"https:\/\/www.cloudpro.co.uk\/\" title=\"\" class=\"combined-link\"><\/a><\/p>\n<div class=\"field field-name-body\">\n<p>Cyber criminals have launched a new campaign that targets Sangoma PBX, an <a href=\"https:\/\/www.itpro.co.uk\/software\/28109\/what-is-open-source\">open source<\/a> web GUI that manages communications toolkit Asterisk, security researchers have said.<\/p>\n<p>The attack exploits CVE-2019-19006, a critical vulnerability in Sangoma private branch exchange (PBX), which grants the attacker admin access to the system and gives them control over its functions.<\/p>\n<p>Nearly 1,200 organisations worldwide over\u00a0past 12 months are said to have been\u00a0targeted, with the main purpose of the campaign being to lift\u00a0phone numbers and gain\u00a0live access to compromised <a href=\"https:\/\/www.itpro.co.uk\/search\/voip\">VoIP services<\/a>, according to a <a href=\"https:\/\/blog.checkpoint.com\/2020\/11\/05\/whos-calling-gaza-and-west-bank-hackers-exploit-and-monetize-corporate-voip-phone-system-vulnerability-internationally\/\">blog<\/a> by researchers at Check Point Software.<\/p>\n<p>Countries targeted include the Netherlands, Belgium, US, Columbia, and Germany. However, over half of the attacks so far have been\u00a0aimed at companies based in the UK, in industries such as government, military, insurance, finance, and manufacturing.<\/p>\n<p>\u201cWhile investigating the exploitations, researchers identified several online profiles associated with private Facebook groups that deal with VoIP, and more specifically, SIP server exploitation,&#8221; said researchers Ido Solomon, Ori Hamama and Omer Ventura, in a\u00a0joint blog post.\u00a0<\/p>\n<p>They added that investigations into the source of the attacks suggested that most hackers were based in Gaza, the West Bank, and Egypt.<\/p>\n<p>It was also concluded that the group has mostly tried to gain access to phone numbers, and sell these on to other groups,\u00a0and grant\u00a0access to\u00a0compromised VoIP services\u00a0\u201cto the highest bidders, who can then exploit those services for their own purposes\u201d.<\/p>\n<p>Researchers said that hackers could also use the compromised systems to support\u00a0further attacks, such as using the system resources for <a href=\"https:\/\/www.itpro.co.uk\/digital-currency\/30249\/what-is-cryptocurrency-mining\">cryptocurrency mining<\/a>, spreading laterally across the company network, or launching attacks on outside targets, while <a href=\"https:\/\/www.itpro.co.uk\/security\/29093\/what-is-phishing\">masquerading as representatives from the compromised company<\/a>.<\/p>\n<p>Companies using vulnerable systems have been urged to <a href=\"https:\/\/www.itpro.co.uk\/security\/34616\/the-top-password-cracking-techniques-used-by-hackers\">change all default passwords<\/a> and analyse call billings on a regular basis as well as applying patches to close the CVE-2019-19006 vulnerability that hackers are exploiting. <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>      Rene Millman<\/p>\n<p>        6 Nov, 2020    <\/p>\n<p>      Cyber criminals have launched a new campaign that targets Sangoma PBX, an open source web GUI that manages communications toolkit Asterisk, security researchers have said.<br \/>\nThe attack exploits CVE&#8230;<\/p>\n","protected":false},"author":417,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-41528","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/41528","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/417"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=41528"}],"version-history":[{"count":1,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/41528\/revisions"}],"predecessor-version":[{"id":41529,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/41528\/revisions\/41529"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=41528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=41528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=41528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}