The Phone Bill You Never Made: Six Years of VoIP Toll Fraud Operations
Businesses around the world are unknowingly paying attackers’ phone bills. For over six years, a threat actor we track as INJ3CTOR3 has systematically compromised internet-exposed PBX systems and abused victim SIP trunks to generate fraudulent international call revenue at scale. The operation requires no ransomware, no data theft, and no sophisticated lateral movement — only persistent access to a VoIP server and the ability to route calls through infrastructure the victim already pays for.
This talk reconstructs the evolution of the operation across successive documented campaign generations between 2019 and 2026, culminating in our original analysis of the latest “JOMANGY” campaign. Through analysis of live artifacts, infrastructure, persistence mechanisms, and actor tooling, we show how the operation evolved from opportunistic PBX compromise into a mature telecom-fraud ecosystem engineered for long-term persistence and rapid reinfection.
A central finding of this research is that what initially appeared to be competitor eviction was, in part, the actor silently migrating its own botnet between infrastructure providers. By treating webshell eviction artifacts as historical telemetry rather than simple indicators of compromise, we were able to reconstruct campaign continuity spanning multiple years and infrastructure transitions.
The session covers the economics of International Revenue Share Fraud (IRSF), the technical anatomy of the JOMANGY attack chain, multi-channel self-healing persistence engineering, actor migration methodology, and practical detection and remediation guidance for defenders operating VoIP infrastructure.
This talk combines malware analysis, telecom abuse investigation, and long-term threat tracking to expose a financially motivated ecosystem that has quietly persisted beneath enterprise telephony infrastructure for years.

Abhinav Thakur – Cyble
Abhinav Thakur is a Security Researcher, currently focused on malware research and detection engineering. At Cyble, his role requires hunting & reverse engineering active malware campaigns to building EDR detection capabilities. In the past, he identified & dissected various malware campaigns including – LunoBotnet (a self-healing Linux botnet), ClipXDaemon (an autonomous X11 clipboard hijacker), ShadowHS (a fileless Linux post-exploitation framework).
His background spans both offensive and defensive security areas. He has worked as a malware detection researcher at SentinelOne, conducted embedded and IoT security research at Payatu, and dedicated years to offensive side of Linux malware research building binary infection framework, rootkits, SFX packers and payloads.
He has delivered multi-day trainings at Nullcon and c0c0n across multiple editions, presented at community meetups, and conducted training for public and private sector audiences covering the domain of IoT hacking, reverse engineering, exploit development, and malware analysis.