Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Apache Binary Backdoors on Cpanel-based servers

$
0
0

For the last few months we have been tracking server level compromises that have been utilizing malicious Apache modules (Darkleech) to inject malware into websites. Some of our previous coverage is availablehere and here.
However, during the last few months we started to see a change on how the injections were being done. On cPanel-based servers, instead of adding modules or modifying the Apache configuration, the attackers started to replace the Apache binary (httpd) with a malicious one. This new backdoor is very sophisticated and we worked with our friends from ESET to provide this report on what we are seeing.


Viewing all articles
Browse latest Browse all 8064

Trending Articles