Winnti hackers target other threat actors with new Glutton PHP backdoor
ID: 9366124c-86ca-59f2-be2e-89fd73b19d9f
STIX ID: report--9366124c-86ca-59f2-be2e-89fd73b19d9f
Feed Name: Bleeping Computer
The Winnti (APT41) group is deploying a new modular backdoor called 'Glutton' that provides fileless, in-memory PHP/PHP-FPM execution by injecting malicious code into popular PHP frameworks (ThinkPHP, Yii, Laravel, Dedecms) and Baota panel files; it supports 22 C2 commands for file operations, command execution, PHP evaluation, scanning, and C2 updates, and has been used since late 2023 in attacks in China and the U.S., including operations that target other cybercriminals and deploy the HackBrowserData infostealer to harvest browser-stored credentials and sensitive data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
