Obfuscated PHP Backdoor Uses Remote C2 to Inject SEO Spam into Joomla Sites

Summary
Sucuri analyzed an obfuscated PHP backdoor in a compromised Joomla site. The loader contacts remote C2 servers to retrieve instructions that can redirect visitors or inject spam and other content.
Key points
- The backdoor was injected at the top of the Joomla site's index.php file and used obfuscated PHP strings to hinder signature-based detection.
- It contacts cdn[.]erpsaz[.]com, with cdn[.]saholerp[.]com as a fallback, to retrieve instructions; lashowroom[.]com was decoded but not used.
- The malware sends server-environment information, including host, request path, and user agent, to the remote infrastructure.
- C2 responses can redirect visitors, inject raw page content, or serve fake HTML and XML sitemap content to search crawlers.
- The site owner reported unrelated product links; the investigation found they were delivered dynamically rather than stored in the Joomla database.
- Sucuri removed the code, checked for additional backdoors, reset administrator credentials, and performed a file-integrity check.
Article Details
- Attack Vectors
- Malicious PHP code was injected at the top of the compromised website's index.php file; the initial compromise method was not disclosed.
- Remote responses controlled whether visitors received redirects, directly injected content, fake XML sitemaps, or fake HTML pages.
- Visitor fingerprint data enabled selective delivery of redirects to users and keyword-stuffed content to search engine crawlers.
- Defensive Notes
- Investigators removed the injected code, checked for additional backdoors, and performed a comprehensive file integrity check.
- The site owner was instructed to reset all administrator credentials.
- Monitor for unexpected product links, unauthorized core-file modifications, and suspicious outbound requests.
- Keep the website core and extensions updated, and remove unused, abandoned, or untrustworthy extensions.
- Use a Web Application Firewall to block exploit attempts and, according to the article, prevent outbound C2 communication.
- Use strong, unique administrator passwords and enable two-factor authentication or IP restrictions where possible.
- Avoid world-writable PHP files; the article recommends directory permissions of 755 and file permissions of 644 as a baseline.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | cdn[.]erpsaz[.]com | Primary attacker-controlled C2 domain used to retrieve instructions and send infected-site environment data. |
| DOMAIN | cdn[.]saholerp[.]com | Fallback C2 domain contacted automatically once if the primary returns an empty response. |
| DOMAIN | lashowroom[.]com | Domain identified by the researchers as a dead decoy in the malware's decoded string table; it was never referenced to construct a URL or contacted. |
| URL | hxxp[:]//cdn[.]erpsaz[.]com/admin[.]php | Primary C2 endpoint constructed by the injected PHP loader to fetch instructions. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe PHP code assembled encoded strings from two-character chunks and split sensitive function names to evade signature-based scanners.T1041 · Exfiltration Over C2 ChannelThe loader encoded data collected from $_SERVER and sent it to the attacker through its C2 requests.T1071.001 · Web ProtocolsThe loader used HTTP requests to retrieve instructions from a primary C2 endpoint, with a fallback C2 if the primary response was empty.T1140 · Deobfuscate/Decode Files or InformationThe bootstrap and lookup functions decoded a base64 string table at runtime to recover functions, C2 components, and response-handling strings.T1505.003 · Web ShellA PHP backdoor injected at the top of Joomla index.php allowed remote control of content served by the compromised website.