Spike in Botnet Attacks Targets PHP Servers, IoT Devices, Cloud

  • Automated attacks are increasing against PHP servers, IoT devices, and cloud gateways.
  • Botnets like Mirai, Gafgyt, and Mozi exploit known security flaws and cloud setup errors.
  • PHP-based systems, especially with WordPress and Craft CMS, face high risk due to common vulnerabilities and misconfigurations.
  • Attackers also exploit debugging tools left active in production and seek credentials and API keys on exposed servers.
  • The AISURU botnet can launch massive DDoS attacks and provide residential proxy services for malicious use.

Cybersecurity experts report a surge in automated cyberattacks targeting PHP servers, Internet of Things (IoT) devices, and cloud gateway systems. These attacks, observed worldwide, are carried out by botnets such as Mirai, Gafgyt, and Mozi, which take advantage of known vulnerabilities and cloud misconfigurations to control exposed systems and grow their networks.

- Advertisement -

The Qualys Threat Research Unit detailed in a report shared with The Hacker News that PHP servers are especially targeted because many use popular content management systems like WordPress and Craft CMS. These platforms often have outdated plugins, themes, and insecure storage, making them vulnerable to attacks.

Some major security flaws in PHP frameworks exploited by attackers include CVE-2017-9841 in PHPUnit, CVE-2021-3129 in Laravel, and CVE-2022-47945 in the ThinkPHP Framework. Attackers have also used “/?XDEBUG_SESSION_START=phpstorm” query strings to trigger Xdebug debugging sessions, a tool intended for developers that if left active, can expose sensitive data.

Beyond PHP servers, threat actors search for credentials, API keys, and access tokens on servers exposed to the internet. They also exploit IoT devices using known issues like CVE-2022-22947 in Spring Cloud Gateway, CVE-2024-3721 in TBK DVR models, and misconfigurations in MVPower DVRs that allow unauthorized system command execution.

Much of the scanning activity comes from cloud platforms including Amazon Web Services, Google Cloud, Microsoft Azure, Digital Ocean, and Akamai Cloud. This use of legitimate services helps attackers hide their true locations.

- Advertisement -

James Maude, field CTO at BeyondTrust, explained, “Having access to a vast network of routers and their IP addresses can allow threat actors to perform credential stuffing and password spray attacks at huge scale. Botnets can also evade geolocation controls by stealing a user’s credentials or hijacking a browser session…”

Meanwhile, NETSCOUT identified the AISURU botnet, which can generate distributed denial-of-service (DDoS) attacks exceeding 20 terabits per second. This botnet is mainly composed of consumer broadband routers, CCTV, DVRs, and other customer equipment. According to NETSCOUT, AISURU includes a residential proxy service that allows malicious users to disguise their identity and carry out attacks like HTTPS application-layer DDoS, credential stuffing, spamming, and phishing.

For more details, see the full reports by The Hacker News and NETSCOUT.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin Plunges 7% in Weekend Liquidity Rout to Near $75K

Bitcoin (BTC) plunged over 7% during weekend trading, liquidating approximately $800 million in positions.The...

XRP Eyes $7 Amid Whale Accumulation, RWA Growth

Whales have added 42 new wallets holding over 1 million XRP since January 1,...

Hyperscale hits 500k TPS, peaks over 700k in public test

Radix Hyperscale sustained 500,000 transactions per second (TPS) with peaks over 700,000 TPS during...

JPMorgan Projects Gold Skyrocketing to $8,000 by 2030

JP Morgan projects Gold (XAU/USD) could surge to $8,000 by 2030, a prediction following...

Crypto VC Inflows Hit $1.4B Through Early 2026

Institutional and venture capital commitments to crypto companies reached $1.4 billion at the start...
- Advertisement -

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!