Chinese cybersecurity researchers have uncovered a PHP backdoor, Glutton, believed to be from persistent threat goup Winnti. The malware has been found in China, the US, Cambodia, Pakistan and South Africa, undetected for over a year. The modular code operates within PHP or PHP-FPM optimised process handling on web servers, eliminating digital footprints and avoiding detection. Glutton can be used to extract data or inject malicious code into frequently used PHP frameworks.
FBI spots HiatusRAT malware attacks targeting web cameras, DVRs
The FBI has issued a warning over new HiatusRAT malware attacks scanning for, and affecting, unsecured web cameras and DVRs online. The attackers mainly target