Beima is a previously undocumented Chinese-language PHP web shell observed on compromised WordPress and cPanel servers. It was identified by Cyderes during an investigation into a Bangladesh-based operator who sold access to more than 5,200 hacked websites via Telegram, with many buyers reportedly being Chinese, Malaysian, and Indonesian threat actors. At least 80 compromised sites were found infected with Beima. The malware provides typical web shell functionality including malware upload, data theft, and command-and-control. Reported stealth features include accepting only encrypted commands decrypted with a hardcoded RSA key, communicating with attacker panels over JSON in a way that mimics normal API traffic, uploading payloads into random directories, and manipulating file timestamps to reduce detection. The broader intrusion activity targeted misconfigured WordPress and cPanel environments, including systems with leftover installers, weak credentials, and exposed .env files. Affected victim organizations included universities, government, law enforcement, and military-related entities, with nearly half of the compromised sites in the education sector and about a quarter in government. Cyderes reported that Beima was, at the time of reporting, undetectable by modern security tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Beima is a botnet leveraging a PHP web shell to compromise WordPress and cPanel servers, which are then rented to other threat actors for malicious activity.
Beima is a sophisticated, previously undocumented Chinese-language webshell used for command-and-control (C2), data theft, and malware upload. It features encrypted command handling, stealthy payload upload with timestamp manipulation, and evades detection by blending C2 traffic with normal API calls. It is currently undetectable by most modern security tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.