Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

Apr 3, 2026

Threat actors are increasingly using HTTP cookies as a control channel for PHP-based web shells on Linux servers and to achieve remote code execution, according to findings from the Microsoft Defender Security Research Team.
“Instead of exposing command execution through URL parameters or request bodies, these web shells rely on threat actor-supplied cookie values to gate execution,

Get Free Report & Network Analysis

Please check your email for the free report.