TOLLBOOTH: What's yours, IIS mine
ID: 48463602-6734-5b42-b3c5-bc2893104fee
STIX ID: report--48463602-6734-5b42-b3c5-bc2893104fee
Feed Name: Elastic Security Labs
Elastic Security Labs and Texas A&M System Cybersecurity describe REF3927, an active, large-scale campaign exploiting publicly exposed ASP.NET machine keys to compromise IIS servers and deploy a malicious IIS module (TOLLBOOTH) used for SEO cloaking and webshell access, alongside Godzilla-forked webshells, a modified Hidden kernel rootkit, and GotoHTTP RMM; the report provides detailed malware/rootkit analysis, IoCs (file hashes, domains, endpoints), TTP mapping, a victim count of ~571 globally, and remediation advice including rotating machine keys and removing persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
