Adminer is a legitimate database management tool referenced in the content as being used by attackers to extract data from databases on compromised servers. BI.ZONE reported that, in analysis of compromises affecting at least 500 Russian companies over the past year, attackers commonly breached public-facing web applications, installed gs-netcat for persistence, and then used tools such as Adminer, phpMiniAdmin, and mysqldump for database theft. The activity was associated in the reporting with the threat actor BI.ZONE tracks as Cavalry Werewolf, which overlaps with YoroTrooper and several related clusters, and targeted organizations in Russia including the public sector as well as energy, mining, and manufacturing enterprises. Separately, the content notes that the filename "adminer.php" appears in lists of known backdoor shell filenames searched by shell finder tools; however, the content does not establish Adminer itself as malware or a backdoor shell. No specific Adminer IOC beyond the filename "adminer.php" is provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Please refer to JPCERT/CC’s security alerts [3] , [4] and an advisory [5] regarding the vulnerabilities exploited. [3] Alert Regarding Cross Site Scripting Vulnerability (CVE-2021-20717) in EC-CUBE
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Collecte Données issues de dépôts d’informations (T1213) – Emails (T1213.003) : Exfiltration de 6 911 e-mails des ministères afghans. – Bases de données : Utilisation de Adminer et sqlmap pour vider des bases de données entières de wise.edu.jo et simania.co.il.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate database management tool abused to access and extract data from databases on compromised servers.
A PHP database administration tool that, when left exposed or deployed maliciously on compromised sites, can function as a persistence and access mechanism.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.