Larva-25003: IIS Native Module Malware Used in Targeted Web Server Attacks (Campaign)
ID: 21689c0d-d5dd-5f38-8dd1-e62db13b6409
STIX ID: report--21689c0d-d5dd-5f38-8dd1-e62db13b6409
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-04-30
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Larva-25003 is a targeted campaign attributed to Chinese-speaking actors that compromised poorly secured Microsoft IIS servers in South Korea by registering a malicious native IIS module (via appcmd.exe) to intercept and modify web traffic for redirects, phishing pages, and affiliate monetization. The intruders used a fileless .NET loader to execute webshells in memory, deployed Gh0st RAT for full remote control, and leveraged a custom rootkit (HijackDriverManager) to hide components, blending espionage with monetization tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
