Threat reportMalwareTL-2026-0903

ClockLauncher PHP Backdoor: php-win.exe LOLBin Abuse for Invisible Execution, LocalSystem Persistence, and EDR-Evasive RMM Deployment

highACTIVE

ClockLauncher PHP Backdoor (TL-2026-0903), also tracked as ClockLauncher backdoor, is a high-severity malware campaign, first published 2026-06-22. It has no confirmed attribution, affects Microsoft Windows, maps to 15 MITRE ATT&CK techniques (T1027, T1036.005, T1047), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-0903

Threat ID
TL-2026-0903
Also known as
ClockLauncher backdoor, php-win.exe backdoor
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
27

Malware and tooling in ClockLauncher PHP Backdoor

Malware and tooling: Atera, Bluetrait

How ClockLauncher PHP Backdoor works

A PHP-based backdoor uncovered during a DFIR engagement abuses php-win.exe (the GUI-marked PHP interpreter) to run a malicious PHP script (5.php) completely invisibly. The implant beacons to a cutt.ly shortened URL with CURLOPT_NOBODY, extracts a payload from the utm_source value in the HTTP Location header, URL-decodes and double-Base64-decodes it, and executes it via eval(). It persists as a boot-triggered scheduled task (ClockLauncher) and a Windows service (ClockSystemService) running as LocalSystem, and was used to silently install remote-management agents (Atera, Bluetrait) while evading the tested EDR.

During an incident-response engagement documented by Stephan Berger (dfir.ch), responders identified a stealthy PHP backdoor used for command-and-control and follow-on tool deployment on a compromised Windows host. The intrusion centered on a scheduled task (ClockLauncher) that executed a batch file (run-clock.bat) which in turn launched php-win.exe against a PHP backdoor script named 5.php, all staged under C:\Windows\Temp\{0B1281F3-C9BC-4B85-AD92-0803ED04208F}\php_2\.

The core evasion primitive is the choice of php-win.exe rather than php.exe. The two interpreters are functionally identical, but php-win.exe is compiled and marked as a 'GUI application' rather than a 'console' application in its PE subsystem, so it runs with no visible window and produces no console output. Combined with execution from a randomly-GUID-named Temp subfolder and a benign-sounding 'Clock' naming scheme for the task and service, this kept the activity low-visibility. In the responders' testing, one EDR raised only a single medium-severity alert for an attempted Atera installation and generated zero alerts for the PHP execution itself or for the Bluetrait agent installation.

The backdoor's C2 logic is a header-channel design. Using cURL, the script issues a request to a hardcoded cutt.ly shortened URL (https://cutt.ly/praXEwzs) with CURLOPT_NOBODY enabled (HEAD-style request, headers only) and CURLOPT_FOLLOWLOCATION enabled. It then scans the returned HTTP headers for a line containing 'utm_source=', extracts that value from the Location/redirect header, applies urldecode() followed by a double base64_decode(), and runs the resulting PHP via eval('?>' . $response). This effectively hides the operator's command/second-stage code inside what looks like an ordinary analytics tracking parameter on a redirect. Beaconing cadence is randomized with sleep(rand(10, 30)), introducing 10-30 second jitter between requests to blend with normal traffic and frustrate signature-based timing detection.

The operators used the implant as a delivery mechanism for legitimate remote-monitoring-and-management (RMM) software, a common tradecraft pattern for durable, EDR-tolerated remote access. An attempted Atera deployment was observed, and a Bluetrait MSP agent was downloaded from https://dfir.bluetrait.io/simple/msp_download_agent?os=windows&access_key=c236ddf4-a046-4b5f-ab80-868565498ca2 and installed silently (msiexec /i setup.msi /qn). A Pastebin raw URL (https://pastebin.com/raw/HZTqJLAs) was used as a test payload host during analysis. Bluetrait installation generated a Windows Security Event ID 7045 (service installation) artifact.

Persistence and privilege are anchored at the highest level: the ClockLauncher scheduled task (C:\Windows\System32\Tasks\ClockLauncher) runs at boot, at RunLevel HighestAvailable, as SYSTEM (S-1-5-18); task XML shows a start boundary of 2025-04-01 and a registration/creation timestamp of 2025-10-01 05:44:26 UTC by a COMPANY\ADM administrative account. The companion ClockSystemService Windows service is configured to run as LocalSystem (it was stopped at the time of investigation). The report attributes the campaign to no known threat actor and identifies no associated CVE; severity is assessed HIGH on the basis of confirmed LocalSystem persistence, defense evasion, and EDR-evasive remote-access tooling. Recommended hunting includes reviewing AutoRuns/scheduled-task inventories for suspicious boot tasks and watching for php-win.exe spawned by cmd.exe/batch files from non-standard paths.

MITRE ATT&CK techniques used in TL-2026-0903

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts

Execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1059.003 Windows Command Shell; T1569.002 Service Execution

Persistence

T1053.005 Scheduled Task; T1543.003 Windows Service

Privilege Escalation

T1053.005 Scheduled Task; T1543.003 Windows Service

Command and Control

T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1219 Remote Access Tools

Affected products and versions in ClockLauncher PHP Backdoor

  • Microsoft — Windows
    Vulnerable versions: Windows hosts with PHP/php-win.exe available
  • The PHP Group — PHP (php-win.exe interpreter)
    Vulnerable versions: PHP 8.4 (C:\php8.4 observed on host)

Remediation for ClockLauncher PHP Backdoor

Immediate actions

  • Hunt for and remove the ClockLauncher scheduled task (C:\Windows\System32\Tasks\ClockLauncher) and the ClockSystemService Windows service
  • Delete the staging directory C:\Windows\Temp\{0B1281F3-C9BC-4B85-AD92-0803ED04208F}\php_2\ and its contents (5.php, run-clock.bat, php-win.exe)
  • Block the C2 shortlink https://cutt.ly/praXEwzs and the cutt.ly domain at the perimeter/proxy
  • Audit for unauthorized RMM installations (Atera, Bluetrait) and revoke/rotate the associated Bluetrait access key c236ddf4-a046-4b5f-ab80-868565498ca2

Workarounds

  • Remove or restrict php-win.exe / PHP CLI on servers that do not require it
  • Disable creation of scheduled tasks and services by non-administrative or unexpected accounts via monitoring of Event ID 4698 (task created) and 7045 (service installed)

Longer-term hardening

  • Deploy EDR/behavioral detection for php-win.exe execution and for interpreters spawning from C:\Windows\Temp
  • Application-control (WDAC/AppLocker) to block unsigned/unexpected php-win.exe and rogue MSI installs
  • Enforce an RMM allowlist and alert on installation of non-sanctioned remote-access agents
  • Egress filtering and TLS inspection to flag HEAD-only beacons and analytics-parameter abuse

Weaknesses (CWE) in ClockLauncher PHP Backdoor

CWE-506, CWE-94

Timeline of ClockLauncher PHP Backdoor

  • ClockLauncher scheduled task XML start boundary set to 2025-04-01 (boot trigger), backdating the task's effective activation window.
  • Attempted Atera RMM installation generated the only EDR signal observed — a single medium-severity alert; the PHP execution itself produced zero alerts.
  • Bluetrait MSP RMM agent downloaded from dfir.bluetrait.io and installed silently via msiexec /i setup.msi /qn for durable, EDR-tolerated remote access.
  • Companion ClockSystemService Windows service installed to run as LocalSystem for redundant persistence (Security Event ID 7045).
  • ClockLauncher scheduled task registered at 05:44:26 UTC by a COMPANY\ADM administrative account, running as SYSTEM (S-1-5-18) at RunLevel HighestAvailable (Security Event ID 4698).
  • DFIR incident-response engagement surfaces the suspicious ClockLauncher boot task; the ClockSystemService is found stopped, leading to discovery and dissection of the php-win.exe backdoor staged under C:\Windows\Temp.
  • cURL header-retrieval demonstration captured at 21:23:36 GMT shows the HEAD beacon following a redirect and extracting the utm_source value from the Location header (example redirect: https://dfir.ch/posts/sysrv/?utm_source=dfir.ch).
  • Analysis discussed publicly on Hacker News, broadening detection-engineering awareness of php-win.exe LOLBin abuse.
  • Stephan Berger publishes the technical dissection of the PHP backdoor on dfir.ch, documenting the php-win.exe GUI-subsystem abuse, header-channel C2, double-Base64 eval() chain, and Clock* persistence.

Sources cited for ClockLauncher PHP Backdoor

Detection coverage for TL-2026-0903

As of 2026-06-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0903 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats