Glutton is a modular PHP backdoor framework targeting PHP web applications and control panels, including Baota and applications built with ThinkPHP, Yii, Laravel, and Dedecms. It executes within PHP or PHP-FPM processes, injects malicious PHP into application files, and deploys additional PHP and ELF backdoors. Its components support remote command execution, file operations, PHP code execution, collection of host and PHP environment information, theft of Baota panel credentials and management data, and retrieval and execution of follow-on payloads. Glutton establishes persistence by modifying application files and system startup configuration, and can operate over UDP or TCP. It has been observed embedded in fraudulent or illicit business software distributed in cybercrime ecosystems, enabling compromise of operators who deploy such software. Observed victims were primarily located in China and the United States, including IT services, business operations, and social-security organizations. The name Glutton has also been used for a separate webshell framework; the PHP backdoor framework is a distinct malware entity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GLUTTON : framework de webshells (JSP, ASPX, .NET, Node.js) avec transport stéganographique PNG, obfuscation Unicode/XML.
This investigation uncovered a previously undocumented advanced PHP backdoor, which we named Glutton due to its ability to infect large numbers of PHP files and implant l0ader_shell.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
To achieve persistence, it appends the following command to /etc/init.d/network
The php_modify task targets popular PHP frameworks such as ThinkPHP, Yii, Laravel, and Dedecms, injecting malicious code for further payload execution.
GLUTTON used XOR encryption, compression, Base64, randomized identifiers, encoded strings, invisible characters, and control-flow flattening; downx.aspx XORed transferred files with key 0xAA.
The webshell tooling itself, a custom framework the operators called GLUTTON, hid its payloads inside PNG image files using steganography.
The elf_install task downloads the Winnti backdoor, masquerading it as /lib/php-fpm.
All code execution occurs within PHP or PHP-FPM (FastCGI) processes, ensuring no file payloads are left behind, thus achieving a stealthy footprint.
The operator divided the LSASS dump into 37 blocks... and reconstructed the complete file.
The operator also collected the SAM and SYSTEM registry hives.
We speculate that the attackers use multiple methods to spread Glutton, including: Leveraging weak password brute-forcing techniques.
Supports both TCP and UDP, defaulting to UDP for communication.
Webshells used HTTP requests for command execution, SQL and file retrieval, while SecBox supported HTTP task routes including GET /task/{id}, POST /task, and POST /upload.
SecFlow designated authenticated SOCKS5 routes at 43.162.217.10:35888 and 103.45.65.93:35888; the operator retrieved LSASS dump blocks through an authenticated SOCKS route.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ASPX webshell framework used as a persistent operational backbone for command execution, internal database queries, credential-material collection, and payload deployment. It conceals executable payloads in PNG RGB pixel data, then uses a server-side decoder to XOR-decrypt and load code directly into memory.
Multi-language webshell framework supporting JSP, ASPX, .NET, and Node.js payloads. It employs PNG steganographic transport with an XOR key, plus Unicode/XML obfuscation, to support persistence and remote command execution on compromised web applications.
A webshell-generation and remote-session-management capability integrated with SecFlow. It generates obfuscated server-side webshells and in-memory loaders for Java, .NET, and Node.js, including PNG-steganographic payload transport. Its generated components can execute commands, manage files and processes, query databases, inject memory-resident components, collect credentials, perform network forwarding, and conceal traffic using encryption, encoding, compression, and code obfuscation.
PHP backdoor used in attacks across multiple countries; attributed with moderate confidence to Winnti per the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.