Listen to this Post
Critical PHP Vulnerability Under Attack
Cybercriminals are actively exploiting a severe security flaw in PHP, known as CVE-2024-4577, to deploy cryptocurrency miners and remote access trojans (RATs) like Quasar RAT. This vulnerability affects Windows-based systems running PHP in CGI mode, allowing attackers to execute arbitrary code remotely.
Security firm Bitdefender has observed a sharp rise in exploitation attempts targeting this vulnerability, particularly since late last year. The majority of attacks have been reported in:
– Taiwan (54.65%)
– Hong Kong (27.06%)
– Brazil (16.39%)
– Japan (1.57%)
– India (0.33%)
How Attackers Are Exploiting the Vulnerability
Around 15% of detected attempts involve basic vulnerability checks, such as running commands like whoami and echo <test_string>. Another 15% focus on system reconnaissance, gathering network details, user information, and system metadata.
More concerningly, about 5% of attacks have led to the deployment of cryptocurrency miners like XMRig. Some cybercriminals have also used Nicehash miners, disguising them as legitimate applications (e.g., javawindows.exe) to evade detection.
In addition to cryptojacking, some attacks have deployed Quasar RAT, a powerful open-source remote access trojan that allows hackers to control infected machines. Other observed attacks have executed malicious Windows Installer (MSI) files, further expanding the scope of the security threat.
A Strange Twist: Hackers Fighting Each Other?
Bitdefender researchers have noticed an unusual trend in these attacks—some threat actors are actively modifying firewall settings on compromised servers to block access to known malicious IPs.
This suggests a turf war between cryptojacking groups, where rival hackers are trying to secure infected systems for themselves by preventing other attackers from hijacking their resources. This tactic aligns with past cryptojacking trends, where malware operators terminate competing miners before deploying their own.
PHP Users Advised to Patch Immediately
The best defense against this exploit is to update PHP to the latest version. Keeping systems up to date ensures protection against known vulnerabilities and prevents unauthorized remote code execution.
Additionally, organizations should restrict the use of Living Off The Land (LOTL) tools, such as PowerShell, to only privileged users like administrators. This can help limit an attacker’s ability to execute malicious scripts on compromised systems.
What Undercode Says:
The CVE-2024-4577 vulnerability is another clear example of how exploitable security flaws can quickly become a battleground for cybercriminals. Several key insights emerge from this attack trend:
1. Cryptojacking Remains a Profitable Cybercrime
Despite growing awareness and security measures, cryptojacking remains a lucrative activity for hackers. The fact that attackers are fighting over access to compromised machines shows the high value of hijacked computing power.
- Living Off The Land (LOTL) Tactics Are Gaining Popularity
Rather than deploying standalone malware, attackers are using LOTL techniques—leveraging built-in system tools like PowerShell, cmd.exe, and MSI installers. This makes their actions harder to detect, as they appear to be legitimate system processes rather than foreign threats.
3. Open-Source Malware Is A Growing Concern
The use of Quasar RAT highlights a broader issue: open-source malware tools are increasingly being weaponized by cybercriminals. These tools are freely available and regularly updated, making them an attractive option for attackers looking for ready-made solutions.
4. Vulnerability Exploits Are Being Automated
The rapid spread of CVE-2024-4577 attacks suggests that cybercriminals are using automation to scan for and exploit vulnerable systems. This means that unpatched servers can be compromised within minutes of being exposed online.
5. Defenders Must Think Like Attackers
Organizations need to proactively monitor for signs of exploitation, including:
– Unusual system processes (e.g., XMRig miners disguised as legitimate apps)
– Unauthorized network connections
– Changes to firewall rules
– Abnormal PowerShell activity
6. PHP Security Must Be Taken More Seriously
Many web applications still rely on outdated PHP versions, leaving them exposed to critical vulnerabilities. Regular security audits and strict patch management policies should be mandatory for businesses using PHP-based systems.
- The Battle for Resources Among Hackers Is Escalating
The fact that hackers are sabotaging each other to maintain control over infected systems is fascinating. It suggests that some cybercriminal groups operate with structured, long-term strategies, treating compromised machines as assets to protect and maintain.
8. Organizations Need A Layered Security Approach
Updating PHP alone
- Endpoint Detection & Response (EDR) to catch suspicious activities
- Strict user access controls to prevent privilege escalation
– Application whitelisting to block unauthorized software execution
– Network segmentation to contain potential breaches
9. Threat Intelligence Should Be Used Proactively
Security teams should stay updated with real-time threat intelligence feeds to track new vulnerabilities and attack trends. Prevention is always cheaper and more effective than dealing with a full-blown security breach.
10. The Need for International Cybersecurity Collaboration
Since CVE-2024-4577 is being actively exploited worldwide, a coordinated response from governments, security firms, and industry leaders is necessary to mitigate its impact.
Final Thoughts
This PHP vulnerability is a wake-up call for organizations relying on outdated systems. Cybercriminals are evolving, using more sophisticated methods and even fighting each other over access to resources. The best defense is proactive security measures, including regular patching, restricted tool access, and advanced threat monitoring.
Fact Checker Results:
- CVE-2024-4577 is a confirmed vulnerability affecting PHP in CGI mode, allowing remote code execution.
- Cryptojacking groups have been observed competing for infected machines by modifying firewall rules.
- Updating PHP and restricting the use of PowerShell and other administrative tools can significantly reduce the risk of exploitation.
References:
Reported By: https://thehackernews.com/2025/03/hackers-exploit-severe-php-flaw-to.html
Extra Source Hub:
https://www.reddit.com
Wikipedia
Undercode AI
Image Source:
Pexels
Undercode AI DI v2





