Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers
ID: 3302cdb9-df41-560f-ba96-a7bbedfbac8c
STIX ID: report--3302cdb9-df41-560f-ba96-a7bbedfbac8c
Feed Name: The Hacker News
Microsoft Defender research describes a stealthy technique where threat actors use HTTP cookie values to control PHP web shells on Linux web servers, allowing remote code execution only when specific cookie markers are present. Attackers combine obfuscated PHP loaders, cookie-gated activation, and cron-based “self-healing” persistence (recreating loaders if removed), often after initial access via valid credentials or exploitation of known vulnerabilities. Microsoft recommends enforcing MFA, monitoring logins and cron jobs, restricting shell execution, and auditing web-directory file creation to detect and mitigate these abuses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
