logo

Statistics Report on Malware Targeting Windows Web Servers in Q4 2025

ID: d3905d0c-4d46-525c-91a9-65409ed31299

STIX ID: report--d3905d0c-4d46-525c-91a9-65409ed31299

Feed Name: ASEC

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC documents Q4 2025 attacks on Windows web servers where threat actors (including Andariel) used web shells to run commands via IIS, deployed TigerRAT as a backdoor, leveraged privilege-escalation utilities (PetitPotato, PrintSpoofer) and ProcDump to steal credentials, and installed coin miners; the report includes IOCs (MD5s, URLs, FQDN) and captures of C2 authentication behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.