Microsoft reported a campaign targeting Linux hosting environments in which threat actors used HTTP cookies as a covert control channel for PHP webshells, allowing malicious code to stay dormant unless specific cookie values were supplied. The webshells avoided obvious command delivery through URL parameters or request bodies by reading attacker input from PHP’s $_COOKIE superglobal, and Microsoft observed multiple variants including layered loaders, direct cookie-driven stagers, and interactive cookie-gated shells for command execution and file upload. The activity was mapped to MITRE ATT&CK techniques including T1190, T1505.003, T1027, T1140, T1105, T1059.004, T1053.003, and T1222.002.
In investigated intrusions, attackers gained access through valid credentials or exploitation of known vulnerabilities, then established durable persistence by abusing legitimate hosting features such as cPanel workflows, jailshell, and cron jobs to repeatedly recreate obfuscated PHP loaders in web-accessible directories. Microsoft said the tradecraft relied on multi-layer obfuscation, runtime reconstruction of functions, and self-healing deployment patterns that reduced visibility in normal traffic and application logs while preserving remote code execution. The company urged defenders to enforce MFA, monitor unusual logins, restrict web server and shell interpreter execution, audit scheduled tasks, inspect suspicious file creation in web directories, and limit hosting control panel shell capabilities while enabling Defender protections on Linux.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft Defender Security Research publicly described a campaign in which PHP webshells on Linux servers used HTTP cookies as a covert control channel, detailing multiple variants, layered obfuscation, and MITRE ATT&CK mappings.
After compromise, the attackers used legitimate hosting features such as cPanel workflows, jailshell, and cron jobs to repeatedly recreate obfuscated PHP loaders in web-accessible directories, creating durable self-healing persistence.
In investigated incidents, threat actors gained initial access to Linux hosting servers using valid credentials or by exploiting a known vulnerability, then deployed PHP-based webshell components on the compromised hosts.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.