logo

BadIIS Malware Abuses IIS Servers For Malicious Traffic Redirection

ID: a6666a59-2c1c-53a0-b097-700cac88caf8

STIX ID: report--a6666a59-2c1c-53a0-b097-700cac88caf8

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Varshini

...
...

The report details the BadIIS campaign: a commercially sold IIS-targeting malware ecosystem used globally (primarily Asia‑Pacific) for traffic redirection, reverse-proxying to manipulate search-engine indexing, content hijacking, and SEO manipulation. Researchers mapped a development timeline via embedded PDB strings (Sept 2021–Jan 2026); the malware is distributed via a builder (MaaS) allowing custom payloads, and uses two-stage installers, C2 authentication, service impersonation, backup persistence, and AV-bypass techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.