# NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date Persistence (February 31st), Fileless Payment Card Skimming, Dropbear SSH C2 Impersonation, Chinese-Nexus eCommerce Targeting

> A sophisticated multi-stage server-side compromise campaign targeting NGINX web servers on Linux eCommerce platforms, discovered by Sansec Threat Research in late 2021. The campaign chains CronRAT (persistence via impossible cron dates) with NginRAT (LD_PRELOAD injection into NGINX worker processes) to achieve stealthy, server-side Magecart payment skimming. The attack hijacks legitimate NGINX processes to intercept and exfiltrate payment card data without modifying the visible web page, bypassing browser-side defenses entirely.

- **Published:** 2021-11-25T12:00:00Z
- **Last reviewed:** 2021-11-25T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0095
- **ID:** TL-2026-0095
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** DORMANT
- **Actor:** MageCart (China)
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

This threat documents the NginRAT and CronRAT server-side web server compromise campaign targeting NGINX-based eCommerce infrastructure, discovered and analyzed by Sansec (Willem de Groot and team) in November-December 2021. The campaign represents a significant evolution in Magecart-style payment skimming from browser-side JavaScript injection to server-side process hijacking.

**CronRAT — Persistence via Impossible Cron Dates (Stage 1):**
CronRAT hides its payload in Linux cron scheduled tasks using an impossible date specification: '52 23 31 2 3' (February 31st). The tasks are syntactically valid but will never execute on schedule — the actual malware code is hidden in the task names, constructed through multiple layers of compression and Base64 decoding. CronRAT features: fileless execution, timing modulation, anti-tampering checksums, custom binary protocol over TCP:443 disguised as Dropbear SSH service, and payload hidden in CRON task names. CronRAT was found present on multiple online stores including a nation's largest outlet and was undetected by all security vendors at discovery. The C2 server at 47.115.46.167 (Alibaba-hosted) accepts custom commands: 'cio' (check-in), 'sd' (self-destruct), 'ev' (eval), 'prm' (parameters for sidekick RAT), 'dwn' (download malicious library). Source: https://sansec.io/research/cronrat

**NginRAT — NGINX Process Parasitism (Stage 2):**
CronRAT downloads and deploys NginRAT, which hijacks a host NGINX application using the Linux LD_PRELOAD mechanism. The attack uses: (1) LD_PRELOAD=/dev/shm/php-shared to intercept dlopen/dlsym calls that NGINX uses for dynamic module loading. (2) LD_L1BRARY_PATH (note: '1' instead of 'I' — intentional obfuscation) containing a ~580-byte decryption key for the RAT payload. (3) nginx --help repeated 50+ times as the injection trigger command. Once NGINX calls dlopen, NginRAT takes control: removes the php-shared library file, changes its process name to 'nginx: worker process' (indistinguishable from legitimate workers), gathers system information, and opens a C2 connection to 47.115.46.167:443. The RAT can then intercept HTTP requests at the server level — before SSL termination — enabling real-time payment data exfiltration without any browser-visible modification. Standard detection methods fail because /proc/PID/exe points to the legitimate nginx binary. Detection requires searching for LD_L1BRARY_PATH (with typo) in /proc/*/environ. Source: https://sansec.io/research/nginrat

**linux_avp — Golang Backdoor (Related Stage):**
Sansec also discovered a related Golang backdoor called linux_avp on eCommerce servers. This self-deleting backdoor disguises itself as a fake 'ps -ef' process, communicates with 47.113.202.35 (Alibaba/Beijing-hosted), and installs persistent crontab entries that download and reinstall the backdoor on reboot. The backdoor uses RSA public key authentication to ensure only the operator can issue commands. Code analysis revealed the author username 'dob' with project codename 'GREECE'. Exfiltration endpoints found at 103.233.11.28 (Hong Kong) for injecting fake payment forms. Source: https://sansec.io/research/ecommerce-malware-linux-avp

**Impact — Server-Side Magecart:**
The campaign represents the evolution of digital skimming from browser-side to server-side. Traditional Magecart attacks inject JavaScript into web pages to capture payment data in the user's browser. This campaign operates at the NGINX process level, intercepting HTTP POST requests containing payment data before they reach the application — and after SSL decryption. This means: (1) Browser-based security tools (CSP, SRI, JS scanners) are completely blind. (2) Network monitoring sees only encrypted traffic to legitimate endpoints. (3) Standard file integrity monitoring doesn't detect the compromise because no files are modified on disk. (4) The malicious NGINX worker is visually identical to legitimate workers. Sansec identified NginRAT instances on eCommerce servers in the US, Germany, and France.

**Attribution:**
Multiple indicators point to Chinese nexus: C2 infrastructure hosted on Alibaba Cloud (47.115.46.167, 47.113.202.35), exfiltration endpoint in Hong Kong (103.233.11.28), and the linux_avp author path suggesting a Chinese-speaking developer. However, specific APT group attribution has not been established — this appears to be financially motivated cybercriminal activity.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1129 Shared Modules
- T1053 Scheduled Task/Job
- T1505 Server Software Component
- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1070 Indicator Removal
- T1027 Obfuscated Files or Information
- T1564 Hide Artifacts
- T1055 Process Injection
- T1140 Deobfuscate/Decode Files or Information
- T1056 Input Capture
- T1082 System Information Discovery
- T1057 Process Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1074 Data Staged
- T1071 Application Layer Protocol
- T1571 Non-Standard Port
- T1001 Data Obfuscation
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1499 Endpoint Denial of Service
- T1574.006 Dynamic Linker Hijacking
- T1053.003 Cron
- T1055.001 Dynamic-link Library Injection
- T1036.005 Match Legitimate Resource Name or Location
- T1070.004 File Deletion
- T1056.003 Web Portal Capture
- T1001.003 Protocol or Service Impersonation
- T1583.004 Server
- T1564.001 Hidden Files and Directories
- T1059.004 Unix Shell
- T1505.003 Web Shell
- T1497.001 System Checks
- T1021.004 SSH
- T1657 Financial Theft

## Sources

- [Sansec: NginRAT — Parasite Targets Nginx](https://sansec.io/research/nginrat)
- [Sansec: CronRAT — Malware Hides Behind February 31st](https://sansec.io/research/cronrat)
- [Sansec: linux_avp Malware Hits eCommerce Sites](https://sansec.io/research/ecommerce-malware-linux-avp)
- [Avast Decoded: Syslogk Linux Kernel Rootkit](https://www.gendigital.com/blog/insights/research/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild)
- [MITRE ATT&CK: T1574.006 — Hijack Execution Flow: LD_PRELOAD](https://attack.mitre.org/techniques/T1574/006/)
- [NGINX Source: ngx_dlopen.h — Dynamic Library Loading](https://github.com/nginx/nginx/blob/a64190933e06758d50eea926e6a55974645096fd/src/os/unix/ngx_dlopen.h)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0095
