Skip to main content

PHP rootkit designed to take over a server

A Dutch developer has created a rootkit that hides in PHP server modules that could be used by attackers to take over web servers.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A Dutch developer has created a rootkit that hides in PHP server modules that could be used by attackers to take over web servers.

Threat details

The PHP rootkit is claimed to be more dangerous than the standard root, a software tool that enables an unauthorised user to gain control of a system.

Rootkits have almost always worked at the lowest level of an operating system (the kernel) to inject malicious content and often hard to detect. An attacker will obtain privileged/administrator access, allowing them to take control of a system and modify the software.

A PHP rootkit is slightly different and has the following qualities:

Accessibility – Writing a rootkit as a PHP module is a lot easier than learning how to write kernel modules.
Stability – Rootkits are designed to run in kernel space, this implies that poorly written malware can crash the entire system. Using PHP rootkits, this problem is intensified. A poorly written PHP rootkit can crash the entire system.
Detectability – PHP Rootkits are difficult to detect because of the lack of checks in PHP modules.
Portability – PHP rootkits are cross-platform rootkits because PHP web applications can be hosted on multiple types of operating systems .

PHP modules are not a common place to hide malware, most rootkits are found in the source code of public websites, .htaccess files, or other files stored in the web server's directories. Since this attack has yet to be used in the wild, it is difficult to fully understand how effective it can be.


Remediation steps

Type Step
Since the Dutch developer claims this rootkit is a persistence tool hackers have always wanted, server administrators are advised to keep a list of the module hashes after installing PHP. It is always recommended to build a new environment if a system is compromised by migrating the data over from a backup.

Last edited: 17 February 2020 11:37 am