Malware.View on attack.mitre.org
PHPsert is a webshell used to execute PHP code that has been in use since at least 2023 against targets in Japan, Singapore, Peru, Taiwan, Iran, Republic of Korea, and the Philippines. PHPsert is not typically deployed as a standalone but integrated into web content such as text editors and content management systems.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
PHPsert can use multiple obfuscation techniques including XOR encoding, hexadecimal character representation, string concatenation, and randomized variable names. |
| T1071.001 Web Protocols |
PHPsert can retrieve remote files using HTTP POST. |
| T1105 Ingress Tool Transfer |
PHPsert has the ability to retrieve remote payloads. |
| T1132.001 Standard Encoding |
PHPsert can use Base64-encoded values in C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
PHPsert has the ability to decode and decrypt obfuscated strings prior to execution. |
| T1505.003 Web Shell |
PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.