Blog | G5 Cyber Security

Attacks in the wild leverage flaw in ThinkPHP Framework

Threat actors in the wild are leveraging a recently discovered flaw in the ThinkPHP framework to install cryptominers, skimmers, and other malware. The flaw was already addressed by the Chinese firm TopThink that designed the framework. Multiple attackers are using relatively simple techniques to trigger the issue. The majority of IP addresses are from the Asia Pacific region where the framework is most popular. In one case, threat actors exploited the flaw to deliver a varian of the Mirai botnet. To secure your system update the framework to the current version.”]

Source: https://securityaffairs.co/wordpress/80018/hacking/thinkphp-framework-attacks.html

Exit mobile version