Beyond the URL: How “Cookie-Gated” Web Shells Hide Silent RCE in Plain Sight
ID: b6f6034e-2759-5b03-8876-a979b8b0224a
STIX ID: report--b6f6034e-2759-5b03-8876-a979b8b0224a
Feed Name: securityonline.info
Microsoft Defender analysis describes a stealth technique where attackers hide PHP web‑shell command-and-control logic inside HTTP cookies, using obfuscated loaders and scheduled tasks to enable durable remote code execution and persistence. The report warns this cookie-gated approach reduces visibility in server logs, can survive remediation via scheduled tasks, and recommends deep inspection of cookie values, file integrity monitoring, and auditing scheduled tasks to detect and mitigate this threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
