Threat reportSupply ChainTL-2026-0095
NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date Persistence (February 31st), Fileless Payment Card Skimming, Dropbear SSH C2 Impersonation, Chinese-Nexus eCommerce Targeting
NginRAT/CronRAT Server-Side Magecart Campaign (TL-2026-0095) is a high-severity supply-chain compromise, first published 2021-11-25. It is attributed to MageCart (China) with medium confidence, maps to 40 MITRE ATT&CK techniques (T1001, T1001.003, T1005), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 40MITRE ATT&CK
- Actors
- 1MageCart
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-0095
- Threat ID
- TL-2026-0095
- Severity
- HIGH
- Status
- DORMANT
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- MageCart
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- eCommerce, Retail, Financial Services, Technology
- Target regions
- United States, Germany, France, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in NginRAT/CronRAT Server-Side Magecart Campaign
Malware and tooling: CronRAT, NginRAT
How NginRAT/CronRAT Server-Side Magecart Campaign works
A sophisticated multi-stage server-side compromise campaign targeting NGINX web servers on Linux eCommerce platforms, discovered by Sansec Threat Research in late 2021. The campaign chains CronRAT (persistence via impossible cron dates) with NginRAT (LD_PRELOAD injection into NGINX worker processes) to achieve stealthy, server-side Magecart payment skimming. The attack hijacks legitimate NGINX processes to intercept and exfiltrate payment card data without modifying the visible web page, bypassing browser-side defenses entirely.
This threat documents the NginRAT and CronRAT server-side web server compromise campaign targeting NGINX-based eCommerce infrastructure, discovered and analyzed by Sansec (Willem de Groot and team) in November-December 2021. The campaign represents a significant evolution in Magecart-style payment skimming from browser-side JavaScript injection to server-side process hijacking.
**CronRAT — Persistence via Impossible Cron Dates (Stage 1):** CronRAT hides its payload in Linux cron scheduled tasks using an impossible date specification: '52 23 31 2 3' (February 31st). The tasks are syntactically valid but will never execute on schedule — the actual malware code is hidden in the task names, constructed through multiple layers of compression and Base64 decoding. CronRAT features: fileless execution, timing modulation, anti-tampering checksums, custom binary protocol over TCP:443 disguised as Dropbear SSH service, and payload hidden in CRON task names. CronRAT was found present on multiple online stores including a nation's largest outlet and was undetected by all security vendors at discovery. The C2 server at 47.115.46.167 (Alibaba-hosted) accepts custom commands: 'cio' (check-in), 'sd' (self-destruct), 'ev' (eval), 'prm' (parameters for sidekick RAT), 'dwn' (download malicious library). Source: https://sansec.io/research/cronrat
**NginRAT — NGINX Process Parasitism (Stage 2):** CronRAT downloads and deploys NginRAT, which hijacks a host NGINX application using the Linux LD_PRELOAD mechanism. The attack uses: (1) LD_PRELOAD=/dev/shm/php-shared to intercept dlopen/dlsym calls that NGINX uses for dynamic module loading. (2) LD_L1BRARY_PATH (note: '1' instead of 'I' — intentional obfuscation) containing a ~580-byte decryption key for the RAT payload. (3) nginx --help repeated 50+ times as the injection trigger command. Once NGINX calls dlopen, NginRAT takes control: removes the php-shared library file, changes its process name to 'nginx: worker process' (indistinguishable from legitimate workers), gathers system information, and opens a C2 connection to 47.115.46.167:443. The RAT can then intercept HTTP requests at the server level — before SSL termination — enabling real-time payment data exfiltration without any browser-visible modification. Standard detection methods fail because /proc/PID/exe points to the legitimate nginx binary. Detection requires searching for LD_L1BRARY_PATH (with typo) in /proc/*/environ. Source: https://sansec.io/research/nginrat
**linux_avp — Golang Backdoor (Related Stage):** Sansec also discovered a related Golang backdoor called linux_avp on eCommerce servers. This self-deleting backdoor disguises itself as a fake 'ps -ef' process, communicates with 47.113.202.35 (Alibaba/Beijing-hosted), and installs persistent crontab entries that download and reinstall the backdoor on reboot. The backdoor uses RSA public key authentication to ensure only the operator can issue commands. Code analysis revealed the author username 'dob' with project codename 'GREECE'. Exfiltration endpoints found at 103.233.11.28 (Hong Kong) for injecting fake payment forms. Source: https://sansec.io/research/ecommerce-malware-linux-avp
**Impact — Server-Side Magecart:** The campaign represents the evolution of digital skimming from browser-side to server-side. Traditional Magecart attacks inject JavaScript into web pages to capture payment data in the user's browser. This campaign operates at the NGINX process level, intercepting HTTP POST requests containing payment data before they reach the application — and after SSL decryption. This means: (1) Browser-based security tools (CSP, SRI, JS scanners) are completely blind. (2) Network monitoring sees only encrypted traffic to legitimate endpoints. (3) Standard file integrity monitoring doesn't detect the compromise because no files are modified on disk. (4) The malicious NGINX worker is visually identical to legitimate workers. Sansec identified NginRAT instances on eCommerce servers in the US, Germany, and France.
**Attribution:** Multiple indicators point to Chinese nexus: C2 infrastructure hosted on Alibaba Cloud (47.115.46.167, 47.113.202.35), exfiltration endpoint in Hong Kong (103.233.11.28), and the linux_avp author path suggesting a Chinese-speaking developer. However, specific APT group attribution has not been established — this appears to be financially motivated cybercriminal activity.
MITRE ATT&CK techniques used in TL-2026-0095
command-and-control
T1001 Data Obfuscation; T1001.003 Protocol or Service Impersonation; T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel
collection
T1005 Data from Local System; T1056 Input Capture; T1056.003 Web Portal Capture; T1074 Data Staged; T1119 Automated Collection
lateral-movement
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1055.001 Dynamic-link Library Injection; T1070 Indicator Removal; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information; T1497.001 System Checks; T1564 Hide Artifacts; T1564.001 Hidden Files and Directories
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1053 Scheduled Task/Job; T1053.003 Cron; T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1129 Shared Modules
discovery
T1057 Process Discovery; T1082 System Information Discovery
initial-access
T1190 Exploit Public-Facing Application
impact
T1499 Endpoint Denial of Service; T1657 Financial Theft
persistence
T1505 Server Software Component; T1505.003 Web Shell
stealth
T1574 Hijack Execution Flow; T1574.006 Dynamic Linker Hijacking
resource-development
Remediation for NginRAT/CronRAT Server-Side Magecart Campaign
Immediate actions
- Check for NginRAT: sudo grep -al LD_L1BRARY_PATH /proc/*/environ | grep -v self/ — any results indicate compromised NGINX processes
- Audit all cron tasks for impossible date specifications (February 31st, June 31st etc.) and encoded payloads in task names
- Check /dev/shm/ for suspicious shared library files: php-shared, www-shared, server-worker-shared, sql-shared, systemd-user.lock
- Kill compromised NGINX processes: kill -9 <PID> for any processes with LD_L1BRARY_PATH in environment
- Block C2 infrastructure: 47.115.46.167, 47.113.202.35, 103.233.11.28 at network perimeter
- Verify nginx binary integrity: compare hash of /usr/sbin/nginx against vendor package
- Audit all NGINX worker processes against expected count and configuration
Workarounds
- Mount /dev/shm with noexec flag to prevent library loading from shared memory
- Restrict LD_PRELOAD via /etc/ld.so.preload whitelist or SELinux policy
- Deploy cron monitoring with alerting on any task modification
- Use immutable infrastructure with regular redeployment cycles
Longer-term hardening
- Deploy server-side file integrity monitoring (AIDE, OSSEC, Tripwire) covering /dev/shm, /tmp, crontab files
- Implement read-only container deployments for NGINX in production (Docker --read-only, Kubernetes readOnlyRootFilesystem)
- Enable Linux audit framework (auditd) rules for LD_PRELOAD usage, cron modifications, and /dev/shm writes
- Deploy runtime application self-protection (RASP) for eCommerce platforms to detect payment data interception
- Implement Content Security Policy and Subresource Integrity for defense-in-depth (browser-side layer)
- Monitor outbound connections from NGINX processes — workers should not initiate external connections
- Use Linux Security Modules (SELinux/AppArmor) to restrict NGINX process capabilities
- Deploy PCI DSS-compliant web application firewalls with server-side skimming detection
- Regular vulnerability scanning of all eCommerce platform plugins and extensions
Weaknesses (CWE) in NginRAT/CronRAT Server-Side Magecart Campaign
Timeline of NginRAT/CronRAT Server-Side Magecart Campaign
- linux_avp Golang backdoor submitted to VirusTotal with comment 'test' — likely by the malware author verifying zero AV detection. Submitted one day after successful eCommerce store breach. Source: https://sansec.io/research/ecommerce-malware-linux-avp
- Sansec Threat Research publishes analysis of linux_avp Golang backdoor targeting eCommerce servers. Self-deleting backdoor with cron persistence, RSA-authenticated C2 at 47.113.202.35 (Alibaba). Author username 'dob', project codename 'GREECE'. 0/0 AV detection at time of writing. Source: https://sansec.io/research/ecommerce-malware-linux-avp
- Sansec exposes CronRAT malware hiding in Linux cron subsystem using impossible dates (February 31st). Found on multiple online stores including nation's largest outlet. Custom binary protocol via TCP:443 to 47.115.46.167 disguised as Dropbear SSH. Undetected by all security vendors. Source: https://sansec.io/research/cronrat
- Sansec discovers NginRAT — CronRAT's second-stage payload that parasitizes NGINX processes via LD_PRELOAD injection. NginRAT hijacks dlopen/dlsym to embed itself in legitimate nginx: worker processes. Uses intentional LD_L1BRARY_PATH typo (1 instead of I) to carry 580-byte decryption key. Instances found in US, Germany, France. Source: https://sansec.io/research/nginrat
- Avast researchers discover Syslogk kernel rootkit based on Adore-Ng, using NGINX-adjacent techniques (LD_PRELOAD, process hiding, magic packet activation) on Centos 6.10 servers. Demonstrates expanding Linux server rootkit ecosystem. Source: https://www.gendigital.com/blog/insights/research/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild
- Server-side Magecart techniques (NGINX process injection, PHP webshells, kernel rootkits) become established pattern. Sansec director Willem de Groot warns: 'Digital skimming is moving from the browser to the server — security professionals should consider the full attack surface.' Browser-side defenses (CSP, SRI) are insufficient.
- As of 2026-05-29, the specific NginRAT/CronRAT server-side Magecart campaign (Sansec, Nov-Dec 2021) shows no documented resurgence, new variant, or active C2 since discovery; all reporting traces to the original 2021 disclosure. Server-side skimming overall stays active via unrelated 2024-26 campaigns (CosmicSting, SessionReaper, Silent Push Jan 2026), but this named operation remains DORMANT with no takedown or direct successor.
Sources cited for NginRAT/CronRAT Server-Side Magecart Campaign
Detection coverage for TL-2026-0095
As of 2021-11-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0095 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.