Malware-as-a-Service Exposed: Cisco Talos Unmasks Developer Behind Prolific “BadIIS” Web Server Toolkit
ID: 42694f6d-0fee-5787-844e-79d5b5708c9a
STIX ID: report--42694f6d-0fee-5787-844e-79d5b5708c9a
Feed Name: securityonline.info
Cisco Talos uncovered a multi-year, commercialized BadIIS Malware-as-a-Service that turns compromised IIS web servers into revenue streams by hijacking browser traffic, performing reverse-proxy SEO spam, and injecting backlinks; analysts attributed development to an author alias "lwxat" via embedded PDB strings, discovered a GUI builder for customized client builds (including a client labeled "x神"), and documented persistence and evasion mechanisms that enable wide resale and long-term server compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
