logo

Q1 2026 malware statistics report for Windows web servers

ID: 5e5b4a35-4dc4-5265-8f00-a30210aaa1fd

STIX ID: report--5e5b4a35-4dc4-5265-8f00-a30210aaa1fd

Feed Name: ASEC

Threat Score
70/100

Date Published: 2026-04-12

Date Updated: 2026-05-12

Author: ATCP

...
...

AhnLab ASEC's Q1 2026 analysis reports that the Larva-26001 actor has been compromising Windows IIS/Tomcat web servers via file upload and RCE, deploying web shells, leveraging privilege escalation techniques (JuicyPotato, BadPotato, CVE-2019-1458) and using port-forwarding tools (HTran/PortTranC) to pivot to internal RDP (port 3389) for backdoor, proxy, and coinminer deployment; recommendations include patching, tightening access controls, and updating antivirus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.