BadIIS Malware Abuses IIS Servers For Malicious Traffic Redirection
ID: a6666a59-2c1c-53a0-b097-700cac88caf8
STIX ID: report--a6666a59-2c1c-53a0-b097-700cac88caf8
Feed Name: Cyber Press
The report details the BadIIS campaign: a commercially sold IIS-targeting malware ecosystem used globally (primarily Asia‑Pacific) for traffic redirection, reverse-proxying to manipulate search-engine indexing, content hijacking, and SEO manipulation. Researchers mapped a development timeline via embedded PDB strings (Sept 2021–Jan 2026); the malware is distributed via a builder (MaaS) allowing custom payloads, and uses two-stage installers, C2 authentication, service impersonation, backup persistence, and AV-bypass techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
