Attackers concealed a PHP web shell inside whitespace appended to a seemingly benign license.php file, using a steganographic technique that encoded the payload in tabs and spaces after legitimate-looking text from the GNU GPL license. The visible PHP code then read its own file, extracted data after the final semicolon, converted whitespace into binary, and applied multiple decoding layers including gzdecode, str_rot13, and base64_decode to rebuild and execute the hidden malware.
The recovered payload was a large web shell capable of file and database operations, information theft, file infection, brute-force activity, and use as a server console or anonymizer on compromised websites. Investigators also found uploader backdoors used to create the fake license.php files and additional malicious changes to .htaccess and index.php, while noting that the whitespace-decoding routine appeared to be adapted from a public proof of concept previously published on Habr.ru.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
According to the analysis, a 2019 Habr.ru article published a proof of concept for whitespace steganography, and the malware's decoder appears to match that technique without modification.
The malware analysis states that the whitespace-only encoding method used by the PHP malware was originally inspired by a 2011 article about encoding data using only tabs and spaces.
Sucuri documented how the visible license.php code read its own file, decoded tab-and-space data appended after the final semicolon, and reconstructed a 74 KB web shell through base64, ROT13, and gzip decoding layers. The analysis also noted fallback execution via a blank-named temporary file and described the web shell's capabilities, including file and database management, information theft, brute-force activity, and anonymization.
Investigators found attackers had hidden a PHP web shell inside whitespace appended to a fake system/license.php file on compromised websites. Additional uploader backdoors were also used to create fake license.php files and inject malicious code into .htaccess and index.php files.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.