logo

BadIIS Malware Turns Hijacks IIS Servers and Redirect Users to Illicit Sites

ID: fcc034b1-3adc-5d55-8e0c-d49a66298907

STIX ID: report--fcc034b1-3adc-5d55-8e0c-d49a66298907

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

BadIIS is a modular MaaS targeting Microsoft IIS servers to silently hijack web traffic and redirect users to illicit sites, manipulate search-engine crawlers, and inject backlink/content for SEO fraud; Cisco Talos analysis links the builder artifact "demo.pdb" and the alias "lwxat" to an actively maintained ecosystem (samples through 2026-01-06) that uses persistence, obfuscation, and auxiliary installers, and the report provides detection guidance and multiple IoCs (ClamAV signatures, Snort SIDs, PDB artifacts, filenames, service names, and custom User-Agent strings).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.