logo

DragonRank Targeting IIS Web Servers (Campaign)

ID: 124b2ec0-924f-5412-a28f-9143e501f511

STIX ID: report--124b2ec0-924f-5412-a28f-9143e501f511

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-09-10

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers have identified the DragonRank campaign targeting IIS web servers across Asia and Europe to deploy web shells (e.g., ASPXSpy) and malware (PlugX, BadIIS) for SEO poisoning, redirecting traffic and hijacking resources. The group exploits web application services (phpMyAdmin, WordPress) to gain footholds, uses DLL sideloading and SEH techniques to load PlugX (with XOR decryption key 0xD1), and employs tools like Mimikatz and PrintNotifyPotato for credential harvesting, lateral movement, and persistence across compromised IIS hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.