BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign
ID: 9cf9b66b-61d2-5838-9006-07f6efbe5b2a
STIX ID: report--9cf9b66b-61d2-5838-9006-07f6efbe5b2a
Feed Name: Elastic Security Labs
Elastic Security Labs observed a large, coordinated REF4033 (UAT-8099) SEO-poisoning campaign that installs BADIIS IIS native modules on Windows web servers—over 1,800 infected globally—to serve keyword-stuffed content to crawlers and redirect real users to gambling, pornography, and cryptocurrency phishing sites; the report documents the attack chain (CbsMsgApi.exe/.dll service persistence, module staging, configuration endpoints), infrastructure and IoCs, and detection/remediation notes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
