PHPsert

S9028

Malware.View on attack.mitre.org

About this malware

PHPsert is a webshell used to execute PHP code that has been in use since at least 2023 against targets in Japan, Singapore, Peru, Taiwan, Iran, Republic of Korea, and the Philippines. PHPsert is not typically deployed as a standalone but integrated into web content such as text editors and content management systems.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

PHPsert can use multiple obfuscation techniques including XOR encoding, hexadecimal character representation, string concatenation, and randomized variable names.

T1071.001
Web Protocols

PHPsert can retrieve remote files using HTTP POST.

T1105
Ingress Tool Transfer

PHPsert has the ability to retrieve remote payloads.

T1132.001
Standard Encoding

PHPsert can use Base64-encoded values in C2 communications.

T1140
Deobfuscate/Decode Files or Information

PHPsert has the ability to decode and decrypt obfuscated strings prior to execution.

T1505.003
Web Shell

PHPsert can use the .php assert function to execute attacker-provided code and maintain persistence on targeted web servers.

Groups that use it0

None recorded.

Campaigns1

References1

  1. sentinelone operationDigitalEye Dec 2024 Open source
    Aleksandar Milenkoski, Luigi Martire. (2024, December 10). Operation Digital Eye | Chinese APT Compromises Critical Digital Infrastructure via Visual Studio Code Tunnels. Retrieved February 27, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.