Statistics Report on Malware Targeting Windows Web Servers in Q4 2025
ID: d3905d0c-4d46-525c-91a9-65409ed31299
STIX ID: report--d3905d0c-4d46-525c-91a9-65409ed31299
Feed Name: ASEC
Threat Score
AhnLab ASEC documents Q4 2025 attacks on Windows web servers where threat actors (including Andariel) used web shells to run commands via IIS, deployed TigerRAT as a backdoor, leveraged privilege-escalation utilities (PetitPotato, PrintSpoofer) and ProcDump to steal credentials, and installed coin miners; the report includes IOCs (MD5s, URLs, FQDN) and captures of C2 authentication behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
