Skip to main content

BadIIS Malware Exploits IIS Servers for SEO Fraud

  • February 10, 2025
  • 0 replies
  • 5 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

February 10, 2025 By Alessandro Mascellino

 

A newly uncovered cyber campaign has been observed exploiting Internet Information Services (IIS) vulnerabilities to distribute malware known as BadIIS.

The attack, affecting several Asian countries, manipulates search engine optimization (SEO) results to redirect users to illegal gambling sites or malicious servers.

Widespread Impact and Financial Motivation

According to Trend Micro’s findings, the attack is financially driven, as many victims are redirected to illicit gambling websites. The campaign has already impacted India, Thailand and Vietnam, with potential threats extending to the Philippines, Singapore, Taiwan, South Korea, Japan, Brazil and Bangladesh.

Compromised IIS servers belong to organizations in various sectors, including government agencies, universities, technology firms and telecommunications companies. Researchers suspect the malware is linked to Chinese-speaking threat actors, based on extracted domain data and Chinese-language code strings found in the samples.

 

>>Full Article<<

0 replies

Be the first to reply!

Reply