Hackers Hijacking IIS Servers in The Wild Using Exposed ASP .NET Machine Keys to Inject Malicious Modules
ID: 582c68bb-f3db-5206-acbf-e40cba585d82
STIX ID: report--582c68bb-f3db-5206-acbf-e40cba585d82
Feed Name: cybersecurityNews.com
Threat Score
A global campaign is actively compromising IIS servers by abusing publicly exposed ASP.NET machine keys to deserialize viewstate and execute code, deploying a malicious IIS module (HijackServer) and a signed kernel rootkit (Wingtb.sys) to maintain persistence and evade detection; the intrusion facilitates SEO fraud and exposes an unauthenticated remote command execution backdoor, impacting roughly 240 server IPs and 280 domains across multiple sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
