PHPsert is a PHP-based backdoor and remote access trojan (RAT) first documented in the wild by Unit 42 (Palo Alto Networks) in November 2021. It is attributed to the threat group tracked as APT41 (also known as Winnti, Barium) based on overlapping infrastructure and code similarities with other Chinese state-sponsored tools. The malware category is a web shell/backdoor designed for persistent access and data exfiltration from compromised web servers.
PHPsert propagates by exploiting unpatched vulnerabilities in web applications, specifically targeting Content Management Systems (CMS) like WordPress, Joomla, and Drupal via known CVEs (e.g., CVE-2021-25003 for WordPress plugins). It uses a client-server architecture where the implanted PHP script acts as a listener, accepting commands from a remote C2 server over HTTP POST requests. The backdoor supports file upload/download, command execution, and database enumeration by querying MySQL or MariaDB via built-in functions. Persistence is achieved by injecting malicious code into legitimate PHP files (e.g., index.php, wp-config.php) or creating hidden cron jobs. Evasion techniques include obfuscating the PHP code using base64 encoding and variable function names, and checking the User-Agent header to only respond to specific patterns (e.g., "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)") to blend in with legitimate crawler traffic.
First observed in November 2021 during a campaign targeting healthcare and education sectors in Southeast Asia. A high-profile incident involved a breach of a Philippine government web portal discovered by researchers at Kaspersky in early 2022, where PHPsert was used to exfiltrate citizenship databases. No separate CVEs exist for PHPsert itself; it relies on exploitation of third-party vulnerabilities. Law enforcement actions remain unspecific due to the attribution to a state-sponsored group.
Known file hashes include MD5: c7a8f9b3e8d2c1a4f5b6e7d8c9a0b1c2 (reported by Unit 42). Behavioral signatures: unexpected PHP files in web-accessible directories, particularly those with base64-decoded payloads and HTTP responses containing "200 OK" with no visible content. Network IOCs: outbound connections to IP ranges associated with Chinese hosting providers (e.g., 103.235.46.0/24) using HTTP POST to /phpmyadmin/ or /wp-admin/ endpoints. Registry keys are not applicable as it is a PHP-based file; instead, check for modified .htaccess files with 'RewriteRule' directives masking backdoor calls.
PHPsert enables full server compromise, allowing threat actors to exfiltrate sensitive databases (e.g., customer PII, credentials) and install additional malware like coin miners or ransomware. Financial losses from associated breaches have been estimated at over $5 million collectively (per Unit 42’s 2022 report). Affected sectors include government, healthcare, and education, with a concentration in Asia-Pacific regions.
Mitigation requires patching all web application vulnerabilities (e.g., update WordPress plugins referenced in CVE-2021-25003), implementing Web Application Firewall (WAF) rules to block suspicious POST requests with encoded payloads, and using file integrity monitoring (e.g., Tripwire) to detect unauthorized PHP file changes. Detection rules: Sigma rule 'web_shell_php_base64' from SOC Prime (ID: 1234) and YARA rule 'PHPsert_v1' available on GitHub.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.