logo

PHP Targeted with Glutton backdoor (Campaign)

ID: e2b3d4a0-9805-59f3-8ba6-1549d0f17cad

STIX ID: report--e2b3d4a0-9805-59f3-8ba6-1549d0f17cad

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2024-12-16

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report describes the Glutton modular PHP backdoor framework that infects PHP files and targets mainstream frameworks (e.g., ThinkPHP, Laravel, Baota), observed across China, the U.S., Cambodia, Pakistan, and South Africa. Linked with moderate confidence to the Winnti group, Glutton embeds l0ader_shell payloads, drops ELF Winnti backdoors disguised as /lib/php-fpm, performs fileless operations, poisons pre-compromised business systems sold on cybercrime forums, and steals browser data via HackBrowserData—thereby exploiting both traditional victims and other cybercriminals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.