Beima PHP is a PHP-based web shell/backdoor used on compromised websites. The provided content states it is injected into websites and then leased to other threat actors for prices ranging from $3 to $200. Its functionality includes remote control of a compromised web server, allowing an attacker to manipulate files, inject arbitrary content, and rename files. The content specifically describes it as a PHP backdoor script and web shell, but does not provide additional high-confidence details on initial infection vectors, specific threat actor attribution, targeted industries, or concrete indicators of compromise beyond its presence as a PHP-based web shell on compromised websites.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PHP webshell/backdoor used to provide remote code execution on compromised servers, enable data theft, and potentially add hosts to a botnet; described as difficult to detect.
A PHP-based web shell/backdoor providing remote control over compromised web servers, used for file manipulation and content injection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.