logo

The Silent Hijack: BADIIS Malware Turns 1,800+ Servers into Illicit Websites

ID: 8482b9c0-a57a-5c0b-92a1-6a354b6a3513

STIX ID: report--8482b9c0-a57a-5c0b-92a1-6a354b6a3513

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Elastic Security Labs details a global SEO-poisoning campaign using the BADIIS malware to infect IIS/Windows servers (over 1,800 victims), serve legitimate content to crawlers while redirecting human search-result visitors to gambling and cryptocurrency scam sites, and monetize compromised university, government, and corporate domains; infrastructure spans major cloud providers and numerous regional ISPs to resist takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.