How a Chinese Webshell Survived 16 Months by Pretending to Be a Joomla Plugin
The short version: A backdoor disguised as a legitimate Joomla plugin called “MetaCache” lived on two websites for sixteen months without triggering any scanner. The attacker used it to walk back in this past weekend. We found it, removed it, and traced the persistence pattern.…