TellYouThePass Ransomware Group Exploits Critical PHP Flaw
ID: b131478c-8234-5bbf-81c8-64eb085eea6b
STIX ID: report--b131478c-8234-5bbf-81c8-64eb085eea6b
Feed Name: Dark Reading
Threat Score
Date Published: 2024-06-12
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
...
...
TellYouThePass is actively exploiting CVE-2024-4577, a PHP CGI argument-injection RCE, to execute arbitrary code and deploy living-off-the-land ransomware via HTA files, mshta.exe, and .NET payloads; a public PoC exists and PHP patches (8.1.29, 8.2.20, 8.3.8) and mitigations (disable CGI, use WAF/AV, patching) are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
