216.73.216.6

Black and White Domination: Glutton Trojan Lurks in Mainstream PHP Frameworks

· Published 11/12/2024 19:24 · Modified 11/12/2024 19:36

Export JSON

Essential information

Published
11/12/2024 19:24
Modified
11/12/2024 19:36
Tags
2024-12-11 backdoor glutton php winnti
Related entities
5 observables, 1 intrusion sets (apt), 15 techniques (mitre), 1 malware, 3 others

Description

The XLab threat detection system uncovered an advanced trojan named , which has been active for over a year without detection. targets both legitimate businesses and cybercriminal operations, infiltrating popular frameworks like ThinkPHP and Laravel. It employs modular components for information theft, installation, and code injection. The malware can deploy both ELF-based backdoors and -based backdoors, demonstrating cross-platform capabilities. Notably, also targets black market operations by infecting their systems, potentially aiming to steal from cybercriminals themselves. The attack framework operates without leaving files on disk, making detection challenging.

External references