logo

BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign

ID: 9cf9b66b-61d2-5838-9006-07f6efbe5b2a

STIX ID: report--9cf9b66b-61d2-5838-9006-07f6efbe5b2a

Feed Name: Elastic Security Labs

Threat Score
78/100

Date Published: 2026-02-11

Date Updated: 2026-04-27

...
...

Elastic Security Labs observed a large, coordinated REF4033 (UAT-8099) SEO-poisoning campaign that installs BADIIS IIS native modules on Windows web servers—over 1,800 infected globally—to serve keyword-stuffed content to crawlers and redirect real users to gambling, pornography, and cryptocurrency phishing sites; the report documents the attack chain (CbsMsgApi.exe/.dll service persistence, module staging, configuration endpoints), infrastructure and IoCs, and detection/remediation notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.