logo

PHP backdoor looks to be work of Chinese-linked APT group

ID: b5030ee9-9fcf-5bfe-9464-ad47a009b2cb

STIX ID: report--b5030ee9-9fcf-5bfe-9464-ad47a009b2cb

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2024-12-16

Date Updated: 2026-04-21

Author: Greg Otto

...
...

QiAnXin XLab uncovered a stealthy, modular PHP backdoor dubbed "Glutton" that runs entirely within PHP/PHP-FPM to avoid leaving file payloads; it can exfiltrate data and inject malicious code into mainstream PHP frameworks (Baota, ThinkPHP, Yii, Laravel). Researchers link Glutton with moderate confidence to the Chinese-linked APT Winnti (APT41), note it targeted multiple countries (including China, the US, Cambodia, Pakistan, and South Africa), and observed the malware may have been active and undetected for over a year despite some uncharacteristic shortcomings in its implementation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.