PHPsert

MITRE ATT&CK: S9028 View on attack.mitre.org

Aliases: PHPsert

First seen
2023-01-01 00:00:00
Malware type
webshell
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 15:31:17

Targeted industries: technology-and-telecommunications

Targeted regions: country_code:jp country_code:sg country_code:pe country_code:tw country_code:ir country_code:kr country_code:ph

Context

PHPsert is a webshell used to execute PHP code that has been in use since at least 2023 against targets in Japan, Singapore, Peru, Taiwan, Iran, Republic of Korea, and the Philippines. PHPsert is not typically deployed as a standalone but integrated into web content such as text editors and content management systems.

Detection coverage

  • 142 Sigma rules

Malware & tools used

  • Web Shell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Web Protocols (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

  • Operation Digital Eye (campaign)

Reports & references

  • MITRE ATT&CK — S9028 (report)
  • sentinelone.com — Operation Digital Eye Chinese Apt Compromises Critical Digital Infrastructure Via Visual Studio Code Tunnels (report)

External references