logo

Hackers Hijacking IIS Servers in The Wild Using Exposed ASP .NET Machine Keys to Inject Malicious Modules

ID: 582c68bb-f3db-5206-acbf-e40cba585d82

STIX ID: report--582c68bb-f3db-5206-acbf-e40cba585d82

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-10-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A global campaign is actively compromising IIS servers by abusing publicly exposed ASP.NET machine keys to deserialize viewstate and execute code, deploying a malicious IIS module (HijackServer) and a signed kernel rootkit (Wingtb.sys) to maintain persistence and evade detection; the intrusion facilitates SEO fraud and exposes an unauthenticated remote command execution backdoor, impacting roughly 240 server IPs and 280 domains across multiple sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.