Tuyul IRC Botnet
First observed in January 2020, Tuyul is a Perl-based Internet Relay Chat (IRC) botnet targeting a known vulnerability in the PHPUnit testing framework.
Summary
First observed in January 2020, Tuyul is a Perl-based Internet Relay Chat (IRC) botnet targeting a known vulnerability in the PHPUnit testing framework.
Affected platforms
The following platforms are known to be affected:
Threat details
Tuyul is delivered using a PHPUnit remote code execution exploit. If successful, it will then connect to one of a number of command and control servers, at which point the attackers will install an obfuscated PHP web shell or connect the system to an IRC botnet. At the time of publication, it is unclear what Tuyul is being used for.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. |
Indicators of compromise
CVE Vulnerabilities
Last edited: 29 June 2021 12:00 pm