Names | PHPsert | |
Category | Malware | |
Type | Backdoor | |
Description | (SentinelLabs) PHPsert executes attacker-provided PHP code using the assert function, which, in PHP versions prior to 8.0.0, interprets and runs parameter strings as PHP code. To hinder static analysis and evade detection, the webshell uses various code obfuscation techniques, including XOR encoding, hexadecimal character representation, string concatenation, and randomized variable names. | |
Information | <https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/> |
Last change to this tool card: 27 December 2024
Download this tool card in JSON format
Changed | Name | Country | Observed | ||
APT groups | |||||
Operation Digital Eye | 2024 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |