PHPsert
MITRE ATT&CK: S9028 View on attack.mitre.org
Aliases: PHPsert
- First seen
- 2023-01-01 00:00:00
- Malware type
- webshell
- Family
- Malware family
- Operating systems
- network-devices
- Profile updated
- 2026-07-07 15:31:17
Targeted industries: technology-and-telecommunications
Targeted regions: country_code:jp country_code:sg country_code:pe country_code:tw country_code:ir country_code:kr country_code:ph
Context
PHPsert is a webshell used to execute PHP code that has been in use since at least 2023 against targets in Japan, Singapore, Peru, Taiwan, Iran, Republic of Korea, and the Philippines. PHPsert is not typically deployed as a standalone but integrated into web content such as text editors and content management systems.
Detection coverage
- 142 Sigma rules
Malware & tools used
- Web Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Web Protocols (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Standard Encoding (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- Operation Digital Eye (campaign)
Reports & references
- MITRE ATT&CK — S9028 (report)
- sentinelone.com — Operation Digital Eye Chinese Apt Compromises Critical Digital Infrastructure Via Visual Studio Code Tunnels (report)