b374k is a PHP web shell/backdoor used to provide remote management and persistent unauthorized access to compromised web servers. The content identifies it as a password-protected remote management tool and notes that implementations may expose a config.php-backed login interface. It is referenced as a persistent PHP web shell alongside WSO, and as a known shell filename commonly searched for by shell finder tools, including b374k.php. Observed use in the provided content includes likely infrastructure management by the North Korean threat actor Kimsuky, specifically a password-protected site at https[://]www.nknews[.]pro/config[.]php assessed as likely implementing b374k. The content also states that attackers exploiting CVE-2025-54236 in Adobe Commerce and Magento Open Source REST API deployments uploaded persistent PHP web shells such as b374k after achieving remote code execution via the /customer/address_file/upload endpoint. After deployment, attackers used such web shells to enumerate the environment, extract configuration data including database credentials and API keys, establish persistence, and in some cases support follow-on actions including customer account hijacking, order manipulation, and exfiltration of personally identifiable information. High-confidence indicators directly mentioned in the content include the filename b374k.php and the likely b374k management URL https[://]www.nknews[.]pro/config[.]php.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exploited vulnerability, CVE-2025-54236, is a critical improper input validation and nested deserialization flaw in the Adobe Commerce and Magento Open Source REST API, specifically affecting the /customer/address_file/upload endpoint. | This enables the upload of persistent PHP webshells, such as variants of WSO and b374k, granting attackers full remote access to the underlying server.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The URL https[://]www.nknews[.]pro/config[.]php hosts a password-protected remote management site, which is likely an implementation of the b374k tool, based on the implementation of the login site and the presence of the config.php file.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PHP webshell used to maintain persistent access on compromised web servers and support follow-on actions including reconnaissance, credential access, and data theft.
b374k is a remote management tool/web shell likely used by Kimsuky for remote management of malicious infrastructure.
A PHP web shell used to maintain covert access on compromised web servers.
b374k is a PHP-based web shell that provides attackers with file management, command execution, and other remote administration capabilities on compromised web servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.