Dissecting a PHP web server rootkit


SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells.

The implant delivers a familiar outcome – on-demand server‑side code execution commonly associated with web shells – but implements it using deeper Linux- and Apache‑specific tradecraft.

Read more…
Source:  Sophos News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • LockBit demands $25 million from Canadian pharmacy chain London Drugs after ransomware attack

    May 23, 2024

    The recent cyber-incident against Canadian pharmacy chain London Drugs was indeed a full-blown ransomware attack, with sensitive data being stolen, and a major ransom being demanded, the company has confirmed. In a statement given to The Register, the company said it had been hit, but stressed it also had no intention of paying the ransom demand. ...

  • ShrinkLocker: Turning BitLocker into ransomware

    May 23, 2024

    The original purpose of BitLocker is to address the risks of data theft or exposure from lost, stolen, or improperly decommissioned devices. Nonetheless, threat actors have found out that this mechanism can be repurposed for malicious ends to great effect. In that incident, the attackers were able to deploy and run an advanced VBS script that ...

  • Most recent cyber attacks on water systems won’t be the last, says cybersecurity expert

    May 23, 2024

    More government agencies are taking steps to shore up their cybersecurity measures. Earlier this week, the Environmental Protection Agency announced it would step up inspections of water facilities that may be vulnerable to cyberattacks. Why are government agencies more at risk when it comes to cyberattacks and operational vulnerabilities? Read more… Source: MSN News Sign up for our Newsletter Related:

  • Cyber Signals: Inside the growing risk of gift card fraud

    May 23, 2024

    Multifactor authentication Security operations In the ever-evolving landscape of cyberthreats, staying ahead of malicious actors is a constant challenge. Microsoft Threat Intelligence has observed that gift cards are attractive targets for fraud and social engineering practices. Unlike credit or debit cards, there’s no customer name or bank account attached to them, which can lessen scrutiny of ...

  • Bank of Russia reports rising number of cyber attacks on financial infrastructure

    May 23, 2024

    The Bank of Russia reported an increase in the number of attacks on suppliers of various IT solutions used in the financial market, the regulator said in its report. “It is particularly noteworthy that attacks on third parties – suppliers of various IT solutions utilized in the financial market – have increased in frequency in 2023. ...

  • Cyber attacks on construction firms jump, new report finds

    May 23, 2024

    A new report has said that cyber attacks on construction companies doubled in the first quarter of this year compared to the same period in 2023. Risk advisory firm Kroll said the increase in attacks was “most likely due to the increased sophistication of business email compromise for either financial gain or as a pivot into ...