CryptoPHP is a threat that uses backdoored Joomla, WordPress, and Drupal themes and plug-ins to compromise webservers on a large scale. By publishing pirated themes and plug-ins free for anyone to use instead of having to pay for them, the CryptoPHP actor is social engineering site administrators into installing the included backdoor on their server.
You can download it from the following link: https://packetstormsecurity.com/files/download/129192/cryptophp-whitepaper-foxsrt-v4.pdf
Source: https://packetstormsecurity.com/files/129192/CryptoPHP-Analysis-Of-A-Hidden-Threat-Inside-Popular-Content-Management-Systems.html