Q1 2026 malware statistics report for Windows web servers
ID: 5e5b4a35-4dc4-5265-8f00-a30210aaa1fd
STIX ID: report--5e5b4a35-4dc4-5265-8f00-a30210aaa1fd
Feed Name: ASEC
Threat Score
AhnLab ASEC's Q1 2026 analysis reports that the Larva-26001 actor has been compromising Windows IIS/Tomcat web servers via file upload and RCE, deploying web shells, leveraging privilege escalation techniques (JuicyPotato, BadPotato, CVE-2019-1458) and using port-forwarding tools (HTran/PortTranC) to pivot to internal RDP (port 3389) for backdoor, proxy, and coinminer deployment; recommendations include patching, tightening access controls, and updating antivirus.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
