logo

Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

ID: 3302cdb9-df41-560f-ba96-a7bbedfbac8c

STIX ID: report--3302cdb9-df41-560f-ba96-a7bbedfbac8c

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-04-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft Defender research describes a stealthy technique where threat actors use HTTP cookie values to control PHP web shells on Linux web servers, allowing remote code execution only when specific cookie markers are present. Attackers combine obfuscated PHP loaders, cookie-gated activation, and cron-based “self-healing” persistence (recreating loaders if removed), often after initial access via valid credentials or exploitation of known vulnerabilities. Microsoft recommends enforcing MFA, monitoring logins and cron jobs, restricting shell execution, and auditing web-directory file creation to detect and mitigate these abuses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.