BadIIS Malware Turns Hijacks IIS Servers and Redirect Users to Illicit Sites
ID: fcc034b1-3adc-5d55-8e0c-d49a66298907
STIX ID: report--fcc034b1-3adc-5d55-8e0c-d49a66298907
Feed Name: cybersecurityNews.com
BadIIS is a modular MaaS targeting Microsoft IIS servers to silently hijack web traffic and redirect users to illicit sites, manipulate search-engine crawlers, and inject backlink/content for SEO fraud; Cisco Talos analysis links the builder artifact "demo.pdb" and the alias "lwxat" to an actively maintained ecosystem (samples through 2026-01-06) that uses persistence, obfuscation, and auxiliary installers, and the report provides detection guidance and multiple IoCs (ClamAV signatures, Snort SIDs, PDB artifacts, filenames, service names, and custom User-Agent strings).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
