Skip to main content

Threats Tagged 'iis'

View all threats tagged with 'iis'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: iis

Threats Tagged 'iis'

Click on any threat for detailed analysis and mitigation recommendations

UAT-8099 is a malware campaign active from August 2025 to early 2026 targeting vulnerable IIS servers, primarily in Asia, with a focus on Thailand and Vietnam. It uses web shells, PowerShell scripts, and the GotoHTTP tool to maintain persistent remote access. New BadIIS malware variants show enhanced persistence, regional customization, and SEO fraud capabilities, with a Linux ELF variant indicating cross-platform targeting. The campaign shares infrastructure with the WEBJACK campaign, suggesting operational overlap. Although no known exploits are reported in the wild, advanced evasion and persistence techniques pose risks to confidentiality, integrity, and availability. European organizations with exposed IIS servers, especially those with business ties to Asia, should be vigilant. Targeted detection of web shells, PowerShell abuse, and monitoring for GotoHTTP traffic are critical mitigations. Germany, France, and the UK are most likely affected due to IIS usage and strategic interests in Asia.

Join the discussion

The 'HijackServer' malicious IIS module is actively compromising IIS servers by exploiting exposed ASP . NET machine keys, enabling unauthenticated remote command execution. This threat, attributed to the RudePanda group, uses a customized rootkit and off-the-shelf tools to maintain persistent access. While primarily used to manipulate search engine results for cryptocurrency scams, the module's capabilities allow attackers or third parties to conduct espionage or build malicious infrastructure. Hundreds of servers worldwide have been affected, indicating a broad impact. The exploitation does not require authentication, and the attack leverages a critical misconfiguration or exposure of sensitive cryptographic keys. European organizations running IIS with exposed ASP . NET machine keys are at risk, especially those in countries with high IIS usage and strategic value. Mitigation requires immediate review and protection of ASP . NET machine keys, deployment of advanced monitoring for rootkit activity, and hardening of IIS configurations.

Join the discussion

AhnLab Security Intelligence Center analyzed attacks on Windows web servers during Q2 2025 using their Smart Defense infrastructure. The study focused on poorly managed servers, categorizing attack types and malware strains. It revealed that multiple threat actors often target vulnerable servers simultaneously, exploiting unpatched systems or misconfigurations. Attackers typically use file upload vulnerabilities to deploy web shells and execute commands, but may also exploit framework or Web Application Server weaknesses. The analysis provides detailed statistics on the number of affected systems and the frequency of attacks, offering insights into the current threat landscape for Windows-based web servers.

Join the discussion

An initial access broker exploited leaked Machine Keys on ASP.NET sites to gain unauthorized access to organizations. The group, tracked as TGR-CRI-0045, targeted industries in Europe and the U.S.including finance, manufacturing, and technology. They used ASP.NET View State deserialization to execute malicious payloads in server memory, minimizing forensic artifacts. The attackers deployed post-exploitation tools for persistence and privilege escalation. The campaign began in October 2024, with increased activity from January to March 2025. Organizations are advised to review and remediate compromised Machine Keys following Microsoft's guidance. The threat group is possibly linked to Gold Melody based on overlapping indicators and tactics.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: iis
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses