PHP backdoor looks to be work of Chinese-linked APT group
ID: b5030ee9-9fcf-5bfe-9464-ad47a009b2cb
STIX ID: report--b5030ee9-9fcf-5bfe-9464-ad47a009b2cb
Feed Name: CyberScoop
QiAnXin XLab uncovered a stealthy, modular PHP backdoor dubbed "Glutton" that runs entirely within PHP/PHP-FPM to avoid leaving file payloads; it can exfiltrate data and inject malicious code into mainstream PHP frameworks (Baota, ThinkPHP, Yii, Laravel). Researchers link Glutton with moderate confidence to the Chinese-linked APT Winnti (APT41), note it targeted multiple countries (including China, the US, Cambodia, Pakistan, and South Africa), and observed the malware may have been active and undetected for over a year despite some uncharacteristic shortcomings in its implementation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
