Skip to main content

PHP Malware Disguised as IonCube Scripts

Malware has been observed that has been disguised to appear almost identical to legitimate scripts produced by the ionCube PHP encoder.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Malware has been observed that has been disguised to appear almost identical to legitimate scripts produced by the ionCube PHP encoder.

Threat details

When executed on a web server running PHP, the malware runs remotely-supplied code which allows a remote attacker access to and control over the system. Over 700 websites have been identified as infected at the time of publication.

Remediation steps

Type Step
  • Do not run PHP scripts from untrusted sources.
  • Use a malware scanner on your web server to identify infections.
  • Ensure patches are applied at the earliest opportunity.

Last edited: 17 February 2020 12:52 pm