PHPsert

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[PHPsert](https://attack.mitre.org/software/S9028) is a webshell used to execute PHP code that has been in use since at least 2023 against targets in Japan, Singapore, Peru, Taiwan, Iran, Republic of Korea, and the Philippines. [PHPsert](https://attack.mitre.org/software/S9028) is not typically deployed as a standalone but integrated into web content such as text editors and content management systems.(Citation: sentinelone operationDigitalEye Dec 2024)

Associated Techniques (6)
ID ATT&CK Tactics
T1027.013 Encrypted/Encoded File -
T1071.001 Web Protocols -
T1105 Ingress Tool Transfer -
T1132.001 Standard Encoding -
T1140 Deobfuscate/Decode Files or Information -
T1505.003 Web Shell -
Metadata
ID: 164505
Created: 28/04/2026 16:00
Updated: 10/05/2026 16:00