Dutch web developer Luke Paris created a rootkit that hides inside a PHP module and attacks servers through Apache modules. Paris created the method to educate others about the potential dangers of malicious PHP modules. The entire rootkit is just 80 lines of code and can easily hide in legitimate modules. This rootkits existence represents a fresh potential attack vector for errant actors and server administrators must start thinking about preventative actions. Experts also suggested businesses should urgently move from SHA-1 to safer alternatives such as SHA-256.”]
Source: https://securityintelligence.com/news/hidden-php-rootkits-unearthed-putting-apache-modules-at-risk/