HomeSecurityPHP vulnerability used to distribute malware and DDoS attacks

PHP vulnerability used to distribute malware and DDoS attacks

Hackers are exploiting a vulnerability in the PHP language to distribute remote access trojans, crypto miners, and distributed denial-of-service (DDoS) botnets.

PHP vulnerability

The vulnerability is tracked as CVE-2024-4577 (CVSS score: 9.8) and allows an attacker to remotely execute malicious commands on Windows. It was publicly disclosed in early June 2024.

“ CVE-2024-4577 is a bug that allows an attacker to escape the command line and pass arguments to be interpreted directly by PHP ,” Akamai researchers Kyle Lefton, Allen West, and Sam Tinklenberg said in a statement . “ The vulnerability involves how Unicode characters are converted to ASCII .”

See also: Ransomware groups invest in custom malware

Akamai observed exploitation attempts against its honeypot servers. Hackers began targeting the vulnerability in the PHP language within the first 24 hours of the disclosure.

Through the PHP vulnerability, the attackers attempted to distribute a remote access trojan called Gh0st RAT, crypto miners like RedTail and XMRig, and a DDoS botnet named Muhstik.

Last month, Imperva also revealed that the CVE-2024-4577 vulnerability was used by hackers to distribute a .NET variant of the TellYouThePass ransomware.

It is recommended that users and organizations that rely on PHP update their installations to the latest version to protect themselves from these attacks.

Beyond updating, some other measures are also needed to avoid malware infection.

See also: ViperSoftX Malware: Appears as an eBook and Distributed via Torrents

malware
PHP vulnerability used to distribute malware and DDoS attacks

Malware protection

Using reliable and up-to-date antivirus software is essential for protection against malware. Antivirus programs can detect and remove malicious software, as well as provide continuous real-time protection.

Next is using strong and unique passwords for each account. Passwords should include a combination of letters, numbers, and special characters to make them harder to crack.

Enabling multi-factor authentication (MFA) adds an extra layer of security. Even if someone gets your password, they'll still need the second factor to gain access.

See also: Check Point: Exploiting compiled V8 JavaScript by malware creators

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, it is also very important to avoid clicking on suspicious links and attachments in emails and messages. Attackers often use phishing emails to trick users into installing malware on their computers.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS