logo

"1.php" Group Intrusion Set Paper

ID: 1bd79e62-6ea2-51f5-80d5-97687e4f6d91

STIX ID: report--1bd79e62-6ea2-51f5-80d5-97687e4f6d91

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

ThreatLabZ reports on the "1.php" Group, an APT-like actor active since at least 2008 that targets China/US relations experts, defense, and geospatial organizations via spearphishing with malicious PDFs or ZIPs that deliver PoisonIvy RAT or similar malware; the group uses web-based C2 checkins (commonly "/1.php?" paths) and sometimes No-IP dynamic DNS domains for C2, and the research provides high-level IOCs while withholding victim-specific details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.