Hackers Exploit Severe PHP Flaw to Deploy Quasar RAT and XMRig Miners
Hackers Exploit Severe PHP Flaw to Deploy Quasar RAT and XMRig Miners
19 March 2025
Threat actors are exploiting a severe security flaw in PHP to deliver cryptocurrency miners and remote access trojans (RATs) like Quasar RAT.
The vulnerability, assigned the CVE identifier CVE-2024-4577, refers to an argument injection vulnerability in PHP affecting Windows-based systems running in CGI mode that could allow remote attackers to run arbitrary code.
Cybersecurity company