{"id":3006,"date":"2025-03-23T12:37:23","date_gmt":"2025-03-23T12:37:23","guid":{"rendered":"https:\/\/aegislens.com\/home\/?p=3006"},"modified":"2025-03-23T12:37:23","modified_gmt":"2025-03-23T12:37:23","slug":"uncovering-how-hackers-use-php-vulnerabilities-to-launch-quasar-rat-and-xmrig-miners","status":"publish","type":"post","link":"https:\/\/aegislens.com\/home\/uncovering-how-hackers-use-php-vulnerabilities-to-launch-quasar-rat-and-xmrig-miners\/","title":{"rendered":"Uncovering How Hackers Use PHP Vulnerabilities to Launch Quasar RAT and XMRig Miners"},"content":{"rendered":"<p>Cybereason recently found evidence that this PHP flaw enables the deployment of Quasar RAT and XMRig miners.<\/p>\n<p>This article reports what we know thus far and provides critical practical advice for cybersecurity professionals.<\/p>\n<p><h2>The Breach: How it Happens<\/h2>\n<\/p>\n<p>The PHP flaw (CVE-2024-4577) attackers exploit is an argument injection vulnerability.<\/p>\n<p>This it stems from incorrect handling of Windows command line arguments when PHP operates in CGI mode.<\/p>\n<p>With successful exploitation, malicious actors could cause arbitrary code execution in affected systems.<\/p>\n<p><h2>Quasar RAT and XMRig Miners Involved<\/h2>\n<\/p>\n<p>In Cybereason\u2019s discovery, hackers used this PHP flaw to deploy Quasar RAT, a fully capable, open-source RAT developed for Windows that leverages TCP protocol for communication between the client and the server.<\/p>\n<p>With Quasar, hackers can remotely administer and monitor infected systems, keystroke logging, and exfiltrate sensitive data.<\/p>\n<p>Moreover, they found XMRig Miner deployment, open-source, cross-platform software used for mining Monero cryptocurrency.<\/p>\n<p>By infecting systems with XMRig, attackers subtly siphon processing power, deploying a &#8220;cryptojacking&#8221; operation to mine cryptocurrency without the victim&#8217;s knowledge.<\/p>\n<p><h2>The Implications<\/h2>\n<\/p>\n<p>This exploit threatens any Windows-based system running PHP in CGI mode.<\/p>\n<p>With the sheer volume of PHP-based applications and websites, the potential damage could be extensive.<\/p>\n<p>The illicit use of system resources for cryptocurrency mining can degrade system performance and increase electricity costs, while a Quasar RAT infection could lead to devastating data breaches.<\/p>\n<p><h2>Practical Advice for Cybersecurity Professionals<\/h2>\n<\/p>\n<p>Firstly, security teams should ensure timely software patching to guard against known vulnerabilities.<\/p>\n<p>PHP&#8217;s official website provides updates and patches, and in this specific incident, the vulnerability has been addressed in PHP 7.2.34, 7.3.23, and 7.4.11.<\/p>\n<p>Furthermore, cybersecurity teams should monitor for abnormal system performance, unusual outbound network traffic, and unfamiliar processes.<\/p>\n<p>Signs like these could indicate an ongoing XMRig Miner or Quasar RAT infection.<\/p>\n<p><h2>Conclusion<\/h2>\n<\/p>\n<p>This exploit serves as a sobering reminder of the relentless creativity of cyber threats and the importance of maintaining a robust cybersecurity infrastructure that includes keeping software up-to-date and actively monitoring for unusual activity.<\/p>\n<p><h3>Follow-Up Reading<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.php.net\/releases\/index.php\">PHP.net &#8211; PHP Releases<\/a><\/li>\n<li><a href=\"https:\/\/cybereason.com\/learn\/quasar-rat\">Cybereason &#8211; Understanding Quasar RAT<\/a><\/li>\n<li><a href=\"https:\/\/www.monero.how\/tutorial-how-to-mine-monero\">Monero &#8211; Tutorial on XMRig Mining<\/a><\/li>\n<\/ul><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybereason recently found evidence that this PHP flaw enables the deployment of Quasar RAT and<\/p>\n","protected":false},"author":1,"featured_media":3009,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[2,5],"tags":[],"class_list":["post-3006","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-news","pmpro-has-access"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/3006","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/comments?post=3006"}],"version-history":[{"count":1,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/3006\/revisions"}],"predecessor-version":[{"id":3010,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/3006\/revisions\/3010"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media\/3009"}],"wp:attachment":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media?parent=3006"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/categories?post=3006"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/tags?post=3006"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}