PHP Malware Disguised as IonCube Scripts
Malware has been observed that has been disguised to appear almost identical to legitimate scripts produced by the ionCube PHP encoder.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Malware has been observed that has been disguised to appear almost identical to legitimate scripts produced by the ionCube PHP encoder.
Threat details
When executed on a web server running PHP, the malware runs remotely-supplied code which allows a remote attacker access to and control over the system. Over 700 websites have been identified as infected at the time of publication.
Remediation steps
Last edited: 17 February 2020 12:52 pm