Glutton is a modular PHP backdoor framework targeting Linux-hosted PHP applications and PHP-FPM environments. It infects application files and operates within PHP processes, enabling remote command execution, file operations, PHP code execution, host-information collection, and retrieval of additional payloads. It can collect credentials and management data from Baota panels, inject malicious code into Baota, ThinkPHP, Yii, Laravel, and Dedecms installations, and deploy both PHP backdoors and an ELF backdoor commonly classified as a Winnti backdoor. Persistence has been implemented through modification of system startup configuration and continued infection of PHP application files. Observed victims include organizations in China and the United States in IT services, business operations, and social security sectors. The framework has also been found embedded in fraudulent or illicit business software distributed in cybercrime ecosystems. Its association with Winnti is assessed with moderate confidence. Glutton should not be conflated with the separately reported GLUTTON multi-platform webshell framework using PNG-based payload concealment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The operators linked infrastructure, reusable accounts, SecFlow files, and GLUTTON payload material. A claimed Apache Shiro success was not supported by recovered evidence, yet it triggered more than 27 unsuccessful GLUTTON follow-up tests.
The operators linked infrastructure, reusable accounts, SecFlow files, and GLUTTON payload material. A claimed Apache Shiro success was not supported by recovered evidence, yet it triggered more than 27 unsuccessful GLUTTON follow-up tests.
The operators linked infrastructure, reusable accounts, SecFlow files, and GLUTTON payload material. A claimed Apache Shiro success was not supported by recovered evidence, yet it triggered more than 27 unsuccessful GLUTTON follow-up tests.
The operators linked infrastructure, reusable accounts, SecFlow files, and GLUTTON payload material. A claimed Apache Shiro success was not supported by recovered evidence, yet it triggered more than 27 unsuccessful GLUTTON follow-up tests.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GLUTTON : framework de webshells (JSP, ASPX, .NET, Node.js) avec transport stéganographique PNG, obfuscation Unicode/XML.
This investigation uncovered a previously undocumented advanced PHP backdoor, which we named Glutton due to its ability to infect large numbers of PHP files and implant l0ader_shell.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
To achieve persistence, it appends the following command to /etc/init.d/network
The php_modify task targets popular PHP frameworks such as ThinkPHP, Yii, Laravel, and Dedecms, injecting malicious code for further payload execution.
confusion_d0c41072a0dc784c.jsp [is an] obfuscated JSP loader for PNG-carried in-memory payloads... downx.aspx [is an] arbitrary-file reader applying XOR with key 0xAA.
The webshell tooling itself, a custom framework the operators called GLUTTON, hid its payloads inside PNG image files using steganography.
The elf_install task downloads the Winnti backdoor, masquerading it as /lib/php-fpm.
All code execution occurs within PHP or PHP-FPM (FastCGI) processes, ensuring no file payloads are left behind, thus achieving a stealthy footprint.
The operator divided the LSASS dump into 37 blocks... and reconstructed the complete file.
The operator also collected the SAM and SYSTEM registry hives.
We speculate that the attackers use multiple methods to spread Glutton, including: Leveraging weak password brute-forcing techniques.
Supports both TCP and UDP, defaulting to UDP for communication.
Webshells used HTTP requests for command execution, SQL and file retrieval, while SecBox supported HTTP task routes including GET /task/{id}, POST /task, and POST /upload.
SecFlow designated authenticated SOCKS5 routes at 43.162.217.10:35888 and 103.45.65.93:35888; the operator retrieved LSASS dump blocks through an authenticated SOCKS route.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A set of payloads and injectors used for post-exploitation of Java application environments. Identified variants target Tomcat/Undertow, WebLogic/CAS, and Redis-assisted deployment, including in-memory filter and PNG-carried loader mechanisms.
A set of server-side payloads/injectors used for Java application-server intrusion activity, including Tomcat, Undertow, WebLogic, CAS, and Redis-oriented variants. Components include in-memory filters, obfuscated JSP/Node.js loaders, and PNG-carried payload loaders. The campaign's claimed Apache Shiro success was not supported, and GLUTTON follow-up tests were unsuccessful.
Custom ASPX webshell framework used as a persistent operational backbone for command execution, internal database queries, credential-material collection, and payload deployment. It conceals executable payloads in PNG RGB pixel data, then uses a server-side decoder to XOR-decrypt and load code directly into memory.
Multi-language webshell framework supporting JSP, ASPX, .NET, and Node.js payloads. It employs PNG steganographic transport with an XOR key, plus Unicode/XML obfuscation, to support persistence and remote command execution on compromised web applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.