← Back to Feed

Agenda Ransomware Deploys Linux Variant on Windows Systems Through Remote Management Tools and BYOVD Techniques

October 23, 2025 · HKCERT · Severity: CRITICAL

Multiple vulnerabilities were identified in PHP. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, security restriction bypass, denial of service condition, sensitive information disclosure and data manipulation on the targeted system. Impact Remote Code Execution Security Restriction Bypass Data Manipulation Denial of Service Information Disclosure System / Technologies affected PHP version prior to 8.5.9 PHP version prior to 8.4.24 PHP version prior to 8.3.33 PHP version prior to 8.2.33 Solutions Before installation of the software, please visit the software manufacturer web-site for more details.

Key Takeaways

  • Trend™ Research identified a sophisticated Agenda ransomware attack that deployed a Linux variant on Windows systems.
  • This cross-platform execution can make detection challenging for enterprises.
☕ Buy a Coffee