logo

TellYouThePass ransomware exploits recent PHP RCE flaw to breach servers

ID: a2343270-6c78-5fd1-913a-69634a6f30e3

STIX ID: report--a2343270-6c78-5fd1-913a-69634a6f30e3

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-06-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

TellYouThePass ransomware quickly weaponized the recently patched PHP RCE (CVE-2024-4577), using publicly available PoC to drop malicious HTA files that run VBScript to load a .NET encryptor in memory via mshta.exe; the malware contacts a C2 disguised as a CSS request, encrypts files, and leaves a READ_ME10.html ransom note demanding ~0.1 BTC. Researchers observed exploitation beginning June 8, and estimates show a large population of exposed PHP servers, increasing the campaign's potential impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.