PHP CGI Flaw Exploited for Webshells in Japan
Attackers are exploiting CVE-2024-4577, a PHP remote code execution flaw on Windows, to plant webshells on Japanese organizations' web servers.
IPA has confirmed active exploitation of CVE-2024-4577, a remote code execution vulnerability in PHP-CGI on Windows, against multiple organizations in Japan. Attackers exploited the flaw to install webshells on affected web services, which the agency warns could be used both for direct network intrusion and as relay points (ORBs, Operational Relay Boxes) to obscure attacker infrastructure or proxy further attacks against other targets.
The advisory situates this activity within a broader trend of 'network-penetrating attacks' targeting internet-facing devices such as VPN appliances, security gateways, and servers at the network perimeter. IPA draws parallels to the Volt Typhoon campaign, which compromised network devices to establish long-term, living-off-the-land persistence against critical infrastructure in the US and allied nations, and to a prior APT campaign against TP-Link routers that similarly converted victim devices into ORB nodes.
CVE-2024-4577 is listed in CISA's Known Exploited Vulnerabilities catalog and affects PHP versions running on Windows, including the 5.x, 7.x, and 8.0.x branches which are now end-of-life. IPA urges all PHP users to apply patches immediately, upgrade unsupported versions, and review network logs for signs of webshell activity or ORB-related traffic even if patches have already been applied.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert_20240705.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free