BadIIS Malware Hijacks IIS Servers, Redirects Users to Malicious Sites
Key Takeaways The BadIIS malware is actively compromising Microsoft Internet Information Services (IIS) web servers. It redirects legitimate website visitors to illicit online destinations, including...
Key Takeaways
- The BadIIS malware is actively compromising Microsoft Internet Information Services (IIS) web servers.
- It redirects legitimate website visitors to illicit online destinations, including gambling and adult content platforms, while manipulating search engine results.
- Discovered by Cisco Talos, this malware operates under a Malware-as-a-Service (MaaS) model, with continuous development since at least September 2021.
- BadIIS employs sophisticated evasion and persistence mechanisms, making detection and removal challenging for administrators.
- Organizations should implement robust monitoring, regular audits of IIS configurations, and keep security solutions updated to counter this threat.
BadIIS Malware Hijacks IIS Servers, Redirects Users to Malicious Sites
A new and persistent threat, dubbed BadIIS malware, is actively targeting web servers running Microsoft’s Internet Information Services (IIS). This malicious software silently infiltrates compromised servers, subsequently diverting unsuspecting users to a variety of illicit online destinations, such as illegal gambling sites and adult content platforms. The campaign has been ongoing for years, impacting thousands of legitimate websites and their users across the Asia-Pacific region, Europe, North America, and South Africa.
Table Of Content
How BadIIS Operates
BadIIS functions by embedding a malicious module directly within the IIS server software. Once installed, this module operates covertly in the background, intercepting web traffic as it passes through the compromised server. It then silently reroutes visitors to attacker-controlled sites without their knowledge, all while the server appears to function normally from an external perspective. This stealthy operation significantly complicates detection for administrators and security teams.
Researchers at Cisco Talos identified a specific variant of BadIIS, characterized by embedded “demo.pdb” strings. This discovery suggests that the malware is a commodity tool, likely distributed or sold among various Chinese-speaking cybercrime groups. According to a report by Cisco Talos, there is moderate confidence that this variant operates under a Malware-as-a-Service (MaaS) model, providing a continuous revenue stream for its developer.
Development and Global Reach
Investigations reveal that BadIIS has been under active development since at least September 2021, with the most recent compiled sample observed on January 6, 2026. The malware undergoes rapid iterative updates, features branching, and incorporates reactive evasion tactics specifically designed to bypass security vendors like Norton. This continuous maintenance underscores the threat actor’s commitment to evolving the malware and its capabilities.
The individual behind this campaign operates under the alias “lwxat,” a handle consistently found within the malware’s builder tool, authentication mechanisms, and even in live HTTP user-agent strings during active command-and-control (C2) communications. Further PDB path artifacts suggest customized builds tailored for specific clients, reinforcing the MaaS business model where different customers receive bespoke versions of the malware.
BadIIS’s Hijacking Capabilities
The core of BadIIS’s functionality lies in its specialized builder tool. Threat actors leverage this tool to generate custom configuration files, JavaScript redirectors, and PHP backlink scripts, which are then injected into the BadIIS binaries. The builder offers four primary capabilities:
- Traffic Redirection: Forcibly sends legitimate users to illicit sites, such as illegal gambling platforms and adult content websites, by injecting JavaScript-based redirectors into the victim’s browser session.
- Reverse Proxying: Manipulates search engine crawlers by acting as a reverse proxy. It fetches illicit content from the attacker’s C2 backend and serves it as if it originated from the legitimate, compromised website.
- Full Content Hijacking: Allows threat actors to completely take over the compromised website’s content, including configuring the percentage of traffic affected and dynamically pulling malicious title, description, and keyword metadata from a remote URL.
- Backlink Injection: Inserts both internal and external backlinks for malicious SEO fraud, boosting the ranking of attacker-controlled sites.
A MaaS Ecosystem Built for Scale
Beyond the primary BadIIS binary, Cisco Talos uncovered a comprehensive suite of auxiliary tools developed by the same author. These include service-based installers, dropper components, and robust persistence mechanisms. These tools ensure that BadIIS automatically reactivates itself whenever a compromised IIS server restarts, significantly complicating manual cleanup efforts. The malware also employs custom Base64 encoding and single-byte XOR obfuscation to hide its C2 server addresses from security scanners.
One of the persistence tools masquerades as legitimate Windows services, such as FaxService or AudiosService, to avoid detection during routine security checks. Another tool functions as a module initialization dropper, packaging the malicious DLL payloads within a standalone executable named “IIS32” and “IIS64” within its resources. Collectively, these components form a modular and scalable ecosystem designed for sustained access and continuous illicit revenue generation.
What You Should Do
- Regularly Audit IIS Modules: System administrators should frequently inspect installed IIS modules and review the
applicationHost.configfile for any unfamiliar or unauthorized entries. - Monitor Network Connections: Implement robust monitoring for unexpected outbound connections originating from web servers.
- Update Security Products: Ensure all security products, including antivirus and intrusion detection systems, are kept up-to-date with the latest threat intelligence and BadIIS-specific signatures (e.g., ClamAV signatures Win.Malware.BadIIS-10069981-0, Win.Malware.BadIIS-10069988-0, Win.Malware.BadIIS-10069984-0, Win.Malware.BadIIS-10069985-0; SNORT rules 1:66400, 1:66439, 1:66438 for Snort2, and 1:66400, 1:301498-1 for Snort3).
- Look for IoCs: Scan for indicators of compromise such as the PDB string “demo.pdb”, the threat actor alias “lwxat” in builder artifacts or HTTP user-agent strings (“lwxatisme”), and file names like “IIS32” or “IIS64” within dropper resources. Also, check for the presence of fake Windows services like “Winlogin”.
- Review PDB Paths: Be aware of developer environment artifacts in PDB paths, such as “C:UsersAdministratorDesktop build paths” or “dll-no904”, which can indicate the presence of this malware.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.