Chinese hackers are targeting the CVE-2018-20062 and CVE-2019-9082 flaws in ThinkPHP applications to install a persistent web shell called Dama .
See also: Exploit for serious Fortinet RCE flaw, update now

The web shell allows for further exploitation of compromised endpoints, such as binding them as part of the attackers' infrastructure to avoid detection in subsequent operations. The first signs of this activity date back to October 2023, but according to Akamai tracking it, the malicious activity has recently expanded and intensified.
Targeting old vulnerabilities
ThinkPHP is an open source web application development framework, which is particularly popular in China.
The flaw CVE-2018-20062, fixed in December 2018, is an issue discovered in NoneCMS 1.3that allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter.
The CVE-2019-9082 affecting ThinkPHP 3.2.4 and earlier, used in Open Source BMS 1.1.1., is a remote command execution issue that was patched in February 2019.
See also: Ivanti: Fixes security flaws in Endpoint Manager
The two ThinkPHP flaws are exploited in this campaign to allow attackers to perform remote code execution, affecting the underlying content management systems (CMS) on the target endpoints.
Specifically, attackers exploit the bugs to download a text file named “public.txt”, which in reality, is the obscure Dama web shell saved as “roeter.php”.

The payload is received from compromised servers located in Hong Kong and provides attackers with remote server control by following a simple authentication step using the password “admin“.
Akamai says that the servers delivering the payloads are themselves infected with the web shell, so it appears that the compromised systems are becoming nodes in the attacker's infrastructure.
The exploitation of these old flaws serves as yet another reminder of the persistent problem of poor vulnerability management, as attackers, in this case, are exploiting security vulnerabilities that were patched long ago.
The recommended action for organizations that may be affected is to move to the latest ThinkPHP version, 8.0, which is secure against known remote code execution flaws. Akamai also notes that the targeting scope of this campaign is broad, even affecting systems that do not use ThinkPHP, which suggests opportunistic motivations.
See also: GitHub warns of SAML auth bypass flaw
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
A web shell, such as the one installed through the ThinkPHP flaws, is a malicious script that is deployed on web servers with the intent of providing attackers with unauthorized access. These scripts can be written in various programming languages, such as PHP, ASP, or Perl, and allow attackers to execute arbitrary commands on the affected server. Once deployed, a web shell acts as a backdoor, allowing continued access to the server without the need for repeated exploitation of vulnerabilities. Detecting and removing web shells can be difficult, as they often mimic legitimate files or processes. Consequently, web servers must employ robust security measures, including regular updates, thorough security audits, and real-time monitoring to mitigate the risks associated with web shells.
Source: bleepingcomputer
