The Silent Hijack: BADIIS Malware Turns 1,800+ Servers into Illicit Websites
ID: 8482b9c0-a57a-5c0b-92a1-6a354b6a3513
STIX ID: report--8482b9c0-a57a-5c0b-92a1-6a354b6a3513
Feed Name: securityonline.info
Threat Score
Elastic Security Labs details a global SEO-poisoning campaign using the BADIIS malware to infect IIS/Windows servers (over 1,800 victims), serve legitimate content to crawlers while redirecting human search-result visitors to gambling and cryptocurrency scam sites, and monetize compromised university, government, and corporate domains; infrastructure spans major cloud providers and numerous regional ISPs to resist takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
