logo

Winnti hackers target other threat actors with new Glutton PHP backdoor

ID: 9366124c-86ca-59f2-be2e-89fd73b19d9f

STIX ID: report--9366124c-86ca-59f2-be2e-89fd73b19d9f

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-12-15

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

The Winnti (APT41) group is deploying a new modular backdoor called 'Glutton' that provides fileless, in-memory PHP/PHP-FPM execution by injecting malicious code into popular PHP frameworks (ThinkPHP, Yii, Laravel, Dedecms) and Baota panel files; it supports 22 C2 commands for file operations, command execution, PHP evaluation, scanning, and C2 updates, and has been used since late 2023 in attacks in China and the U.S., including operations that target other cybercriminals and deploy the HackBrowserData infostealer to harvest browser-stored credentials and sensitive data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.