Threat Advisory

Msupedge Backdoor Exploits PHP Vulnerability on Taiwanese University Systems

Threat: Vulnerability/Malware
Targeted Region: Taiwan
Targeted Sector: Education, Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A newly discovered backdoor, identified as Backdoor.Msupedge, has been detected in an attack against a university in Taiwan. These backdoors employ a rare technique of communication with its command-and-control (C&C) server using DNS traffic. Although DNS tunneling is not entirely new, its application in this context is relatively uncommon, making this threat noteworthy.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A newly discovered backdoor, identified as Backdoor.Msupedge, has been detected in an attack against a university in Taiwan. These backdoors employ a rare technique of communication with its command-and-control (C&C) server using DNS traffic. Although DNS tunneling is not entirely new, its application in this context is relatively uncommon, making this threat noteworthy.[emaillocker id="1283"]

 

Backdoor.Msupedge is distributed as a dynamic link library (DLL) and is found in the following file paths: csidl_drive_fixed\xampp\wuplog.dll and csidl_system\wbem\wmiclnt.dll. The backdoor utilizes DNS tunneling, based on the publicly available dnscat2 tool, to facilitate communication with its C&C server. It processes commands received via DNS name resolution, with different behaviors determined by the third octet of the C&C server’s IP address. Commands include creating processes, downloading files, and managing temporary files. The initial intrusion is suspected to exploit CVE-2024-4577, a recently patched PHP vulnerability involving CGI argument injection. This flaw affects all versions of PHP on Windows systems and can lead to remote code execution if exploited.

 

The initial compromise appears to be linked to the exploitation of a recently patched PHP vulnerability CVE-2024-4577, a CGI argument injection flaw that affects all PHP versions on Windows. This vulnerability can lead to remote code execution if exploited. There has been recent activity from multiple threat actors scanning for systems vulnerable to this exploit. Currently, there is no clear attribution for the attack or understanding of the attackers' motives.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access  T1190 Exploit Public-Facing Application
Execution  T1059 Command and Scripting Interpreter
Defense Evasion T1027 Obfuscated Files or Information
Discovery  T1083 File and Directory Discovery
T1018 Remote System Discovery
 Command and Control  T1132 Data Encoding
T1071 Application Layer Protocol
T1105 Ingress Tool Transfer
 Impact T1565 Data Manipulation

RECOMMENDATION:

  • We strongly recommend you update PHP versions to PHP 8.3.10.

REFERENCES:

The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/hackers-use-php-exploit-to-backdoor-windows-systems-with-new-malware/

[/emaillocker]
crossmenu