logo

Larva-25003: IIS Native Module Malware Used in Targeted Web Server Attacks (Campaign)

ID: 21689c0d-d5dd-5f38-8dd1-e62db13b6409

STIX ID: report--21689c0d-d5dd-5f38-8dd1-e62db13b6409

Feed Name: Wiz Cloud Threat Landscape

Threat Score
82/100

Date Published: 2025-04-30

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Larva-25003 is a targeted campaign attributed to Chinese-speaking actors that compromised poorly secured Microsoft IIS servers in South Korea by registering a malicious native IIS module (via appcmd.exe) to intercept and modify web traffic for redirects, phishing pages, and affiliate monetization. The intruders used a fileless .NET loader to execute webshells in memory, deployed Gh0st RAT for full remote control, and leveraged a custom rootkit (HijackDriverManager) to hide components, blending espionage with monetization tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.