logo

Hackers use PHP exploit to backdoor Windows systems with new malware

ID: 9dde415b-b7eb-5a2c-92b4-9e8c3726f3d4

STIX ID: report--9dde415b-b7eb-5a2c-92b4-9e8c3726f3d4

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-08-20

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Symantec observed a newly discovered Windows backdoor, dubbed Msupedge, deployed at a university in Taiwan—likely via exploitation of the critical PHP-CGI RCE CVE-2024-4577. The attackers dropped two DLLs (weblog.dll loaded by Apache and wmiclnt.dll) and use DNS tunneling (based on dnscat2) for C2, enabling remote commands such as process creation and file download; the report notes active exploitation, public PoC release, and other actors rapidly abusing the same PHP flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.