logo

Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign

ID: a8d7a3ff-77b0-52a0-bd0d-3546ee0fea28

STIX ID: report--a8d7a3ff-77b0-52a0-bd0d-3546ee0fea28

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated global SEO-poisoning campaign using the BADIIS malware has compromised over 1,800 Windows IIS servers across government, education, and financial sectors; BADIIS installs as a native IIS module, inspects User-Agent headers to serve injected SEO content to crawlers while showing clean pages to users, and uses direct system calls to evade EDR, with Elastic Security Labs attributing the activity to threat group UAT-8099.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.