Collected research
Cryptophp Backdoor
CryptoPHP Backdoor Hijacks Servers with Malicious Plugins & Themes
CryptoPHP is a backdoor hidden inside pirated WordPress, Joomla and Drupal plugins and themes that administrators install for free. Once running on the server it gives its operators public-key encrypted command and control, email fallback, remote list updates and self-update, and is used mainly to inject black hat SEO content into the compromised sites.
Record
- Document
- CryptoPHP Backdoor Hijacks Servers with Malicious Plugins & Themes
- Researcher
- Swati Khandelwal
- Published by
- The Hacker News
- Topic
- Crypto
In the archive
Related sources
- CryptoPHP analysis Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Swati Khandelwal, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .