logo

PHP Vulnerability Exploited to Spread Malware and Launch DDoS Attacks

ID: 506bd2ce-7a28-56c1-8da7-443591b00a00

STIX ID: report--506bd2ce-7a28-56c1-8da7-443591b00a00

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-07-11

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Multiple threat actors rapidly began exploiting CVE-2024-4577 (CVSS 9.8) in PHP to escape the command line via Unicode conversion issues and deliver remote access trojans (Gh0st RAT), cryptocurrency miners (RedTail, XMRig), and the Muhstik DDoS botnet; Imperva observed TellYouThePass actors using the flaw to distribute a .NET ransomware variant. Akamai saw exploitation attempts within 24 hours of disclosure, underscoring high exploitability and rapid adoption, while Cloudflare reported increased DDoS activity in Q2 2024; organizations are advised to update PHP immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.