cognitive cybersecurity intelligence

News and Analysis

Search

PHP backdoor looks to be work of Chinese-linked APT group

Chinese cybersecurity researchers have uncovered a PHP backdoor, Glutton, believed to be from persistent threat goup Winnti. The malware has been found in China, the US, Cambodia, Pakistan and South Africa, undetected for over a year. The modular code operates within PHP or PHP-FPM optimised process handling on web servers, eliminating digital footprints and avoiding detection. Glutton can be used to extract data or inject malicious code into frequently used PHP frameworks.

Source: cyberscoop.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts