Black and White Domination: Glutton Trojan Lurks in Mainstream PHP Frameworks
Essential information
- Published
- 11/12/2024 19:24
- Modified
- 11/12/2024 19:36
- Tags
- 2024-12-11 backdoor glutton php winnti
- Related entities
- 5 observables, 1 intrusion sets (apt), 15 techniques (mitre), 1 malware, 3 others
Description
The XLab threat detection system uncovered an advanced PHP trojan named Glutton, which has been active for over a year without detection. Glutton targets both legitimate businesses and cybercriminal operations, infiltrating popular PHP frameworks like ThinkPHP and Laravel. It employs modular components for information theft, backdoor installation, and code injection. The malware can deploy both ELF-based Winnti backdoors and PHP-based backdoors, demonstrating cross-platform capabilities. Notably, Glutton also targets black market operations by infecting their systems, potentially aiming to steal from cybercriminals themselves. The attack framework operates without leaving files on disk, making detection challenging.