logo

Hackers exploit 2018 ThinkPHP flaws to install ‘Dama’ web shells

ID: 9eae7b05-2a3b-5023-a520-ae2a7b5ba318

STIX ID: report--9eae7b05-2a3b-5023-a520-ae2a7b5ba318

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-06-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Chinese threat actors have been exploiting long-patched ThinkPHP vulnerabilities (CVE-2018-20062 and CVE-2019-9082) to install the persistent Dama web shell on vulnerable servers since October 2023; Dama provides remote control, file upload, port scanning, database access, and infrastructure pivoting, and attackers are using compromised hosts as nodes to host further payloads. Organizations are advised to update ThinkPHP to version 8.0 and remediate affected endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.