Product
PHP
- First Reported
- Jul 14, 2025
- Latest Reported
- Oct 1, 2026
Reported Context (4)
- The .user.ini trigger. A single line, auto_prepend_file, points PHP at a loader that runs before every request in that directory tree. This fires even on requests that never reach WordPress. The value is cached by PHP. SC WordPress Malware Uses Self-Rebuilding Loaders and Blockchain-Controlled Backdoor
- New PHP Execution Technique# PolinRider Campaign Spreads Through Compromised GitHub Accounts and Packagist
- implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, Sophos dissects Linux rootkit that hides PHP web shells in BIG-IP APM environments
- This new malware, a shift from the previously identified JavaScript-based Interlock RAT (aka NodeSnake), uses PHP and is being used in a widespread campaign. KongTuke FileFix Campaign Delivers a New PHP-Based Interlock RAT
CVE (1)
Malware (5)
Threat Actors (3)
MITRE ATT&CK (31)
Vendors (4)
Products (13)
Countries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.