Threats Tagged 'iis module'
View all threats tagged with 'iis module'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'iis module'
Click on any threat for detailed analysis and mitigation recommendations
A Chinese-speaking cybercrime group, REF4033, has orchestrated a massive SEO poisoning campaign, compromising over 1,800 Windows web servers worldwide using the BADIIS malware. The campaign operates in two phases: serving keyword-stuffed HTML to search engine crawlers and redirecting victims to illicit websites. The group deploys BADIIS, a malicious IIS module, to hijack legitimate servers for manipulating search engine rankings and facilitating financial fraud. The campaign primarily targets the APAC region, with China and Vietnam accounting for 82% of compromised servers. Victims span various sectors, including government agencies, educational institutions, and financial services. The attackers use sophisticated techniques for stealth and anti-tampering, employing Chinese encryption standards and commercial obfuscation tools. Join the discussion | AlienVault OTX General | 02/17/2026, 17:59:21 UTC Added: 02/17/2026, 18:45:30 UTC |
A Chinese-speaking threat actor group, tracked as CL-UNK-1037, has been conducting a large-scale SEO poisoning campaign called Operation Rewrite. The attackers use a malicious IIS module named BadIIS to intercept and alter web traffic on compromised servers, manipulating search engine results to redirect users to malicious sites. The campaign primarily targets East and Southeast Asia, with a focus on Vietnam. The attackers employ various tools including native IIS modules, ASP.NET handlers, and PHP scripts. The operation shows links to previously known threat groups like Group 9 and possibly DragonRank. The campaign demonstrates sophisticated techniques for search result manipulation and traffic redirection, posing significant risks to unsuspecting internet users. Join the discussion | AlienVault OTX General | 09/25/2025, 09:20:57 UTC Added: 09/25/2025, 14:18:55 UTC |
ESET researchers have identified a new threat actor, GhostRedirector, targeting Windows servers with custom tools. The group has compromised at least 65 servers, mainly in Brazil, Thailand, and Vietnam, across various sectors. Their arsenal includes Rungan, a passive C++ backdoor, and Gamshen, a malicious IIS module for SEO fraud. GhostRedirector also uses public exploits for privilege escalation and creates rogue user accounts to maintain access. The attacks aim to manipulate Google search results, promoting gambling websites through shady SEO techniques. Evidence suggests GhostRedirector is a China-aligned actor, active since at least August 2024. The campaign demonstrates sophisticated tactics for server compromise and long-term access maintenance. Join the discussion | AlienVault OTX General | 09/04/2025, 23:40:48 UTC Added: 09/05/2025, 08:27:07 UTC |
ESET researchers uncovered a cyberespionage campaign by BladedFeline, an Iran-aligned APT group likely tied to OilRig. The group has targeted Kurdish and Iraqi government officials since at least 2017, using various malicious tools including the Whisper backdoor, PrimeCache IIS module, and reverse tunnels. BladedFeline maintains persistent access to high-ranking officials in both the Kurdistan Regional Government and Iraqi government, likely for espionage purposes. The group's toolset includes sophisticated backdoors, webshells, and custom tunneling applications. ESET assesses with medium confidence that BladedFeline is a subgroup of OilRig, based on shared code, targets, and tactics. The campaign also extended to a telecommunications provider in Uzbekistan. Join the discussion | AlienVault OTX General | 06/10/2025, 18:09:11 UTC Added: 06/10/2025, 19:35:03 UTC |
Showing 1 to 4 of 4 results