Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 00:30:42 UTC Home > List all groups > List all tools > List all groups using tool PHPsert Tool: PHPsert Names PHPsert Category Malware Type Backdoor Description (SentinelLabs) PHPsert executes attacker-provided PHP code using the assert function, which, in PHP versions prior to 8.0.0, interprets and runs parameter strings as PHP code. To hinder static analysis and evade detection, the webshell uses various code obfuscation techniques, including XOR encoding, hexadecimal character representation, string concatenation, and randomized variable names. Information Last change to this tool card: 27 December 2024 Download this tool card in JSON format All groups using tool PHPsert Changed Name Country Observed APT groups Operation Digital Eye 2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=368f7e08-8a58-4b34-83d1-6c087a461eb1 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=368f7e08-8a58-4b34-83d1-6c087a461eb1 Page 1 of 1