PHP rootkit designed to take over a server
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Rootkits have almost always worked at the lowest level of an operating system (the kernel) to inject malicious content and often hard to detect. An attacker will obtain privileged/administrator access, allowing them to take control of a system and modify the software.
A PHP rootkit is slightly different and has the following qualities:
Accessibility – Writing a rootkit as a PHP module is a lot easier than learning how to write kernel modules.
Stability – Rootkits are designed to run in kernel space, this implies that poorly written malware can crash the entire system. Using PHP rootkits, this problem is intensified. A poorly written PHP rootkit can crash the entire system.
Detectability – PHP Rootkits are difficult to detect because of the lack of checks in PHP modules.
Portability – PHP rootkits are cross-platform rootkits because PHP web applications can be hosted on multiple types of operating systems .
PHP modules are not a common place to hide malware, most rootkits are found in the source code of public websites, .htaccess files, or other files stored in the web server's directories. Since this attack has yet to be used in the wild, it is difficult to fully understand how effective it can be.
Remediation steps
Last edited: 17 February 2020 11:37 am