Hackers use PHP exploit to backdoor Windows systems with new malware
ID: 9dde415b-b7eb-5a2c-92b4-9e8c3726f3d4
STIX ID: report--9dde415b-b7eb-5a2c-92b4-9e8c3726f3d4
Feed Name: Bleeping Computer
Threat Score
Symantec observed a newly discovered Windows backdoor, dubbed Msupedge, deployed at a university in Taiwan—likely via exploitation of the critical PHP-CGI RCE CVE-2024-4577. The attackers dropped two DLLs (weblog.dll loaded by Apache and wmiclnt.dll) and use DNS tunneling (based on dnscat2) for C2, enabling remote commands such as process creation and file download; the report notes active exploitation, public PoC release, and other actors rapidly abusing the same PHP flaw.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
