Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GhostJacking Attack Hijacks AI Agents to Run Malicious Code on Developer Machines
August 11, 2026
Horizon3.ai Secures $20M to Boost Partner-Led Growth and Ecosystem
August 11, 2026
Chinese Hackers Use Fake DeepSeek Page to Deliver Malware
August 11, 2026
Home/Threats/BadIIS Malware Hijacks IIS Servers, Redirects Users to Malicious Sites
Threats

BadIIS Malware Hijacks IIS Servers, Redirects Users to Malicious Sites

Key Takeaways The BadIIS malware is actively compromising Microsoft Internet Information Services (IIS) web servers. It redirects legitimate website visitors to illicit online destinations, including...

Jennifer sherman
Jennifer sherman
May 21, 2026 4 Min Read
65 0

Key Takeaways

  • The BadIIS malware is actively compromising Microsoft Internet Information Services (IIS) web servers.
  • It redirects legitimate website visitors to illicit online destinations, including gambling and adult content platforms, while manipulating search engine results.
  • Discovered by Cisco Talos, this malware operates under a Malware-as-a-Service (MaaS) model, with continuous development since at least September 2021.
  • BadIIS employs sophisticated evasion and persistence mechanisms, making detection and removal challenging for administrators.
  • Organizations should implement robust monitoring, regular audits of IIS configurations, and keep security solutions updated to counter this threat.

BadIIS Malware Hijacks IIS Servers, Redirects Users to Malicious Sites

A new and persistent threat, dubbed BadIIS malware, is actively targeting web servers running Microsoft’s Internet Information Services (IIS). This malicious software silently infiltrates compromised servers, subsequently diverting unsuspecting users to a variety of illicit online destinations, such as illegal gambling sites and adult content platforms. The campaign has been ongoing for years, impacting thousands of legitimate websites and their users across the Asia-Pacific region, Europe, North America, and South Africa.

Table Of Content

  • Key Takeaways
  • BadIIS Malware Hijacks IIS Servers, Redirects Users to Malicious Sites
  • How BadIIS Operates
  • Development and Global Reach
  • BadIIS’s Hijacking Capabilities
  • A MaaS Ecosystem Built for Scale
  • What You Should Do

How BadIIS Operates

BadIIS functions by embedding a malicious module directly within the IIS server software. Once installed, this module operates covertly in the background, intercepting web traffic as it passes through the compromised server. It then silently reroutes visitors to attacker-controlled sites without their knowledge, all while the server appears to function normally from an external perspective. This stealthy operation significantly complicates detection for administrators and security teams.

Researchers at Cisco Talos identified a specific variant of BadIIS, characterized by embedded “demo.pdb” strings. This discovery suggests that the malware is a commodity tool, likely distributed or sold among various Chinese-speaking cybercrime groups. According to a report by Cisco Talos, there is moderate confidence that this variant operates under a Malware-as-a-Service (MaaS) model, providing a continuous revenue stream for its developer.

Development and Global Reach

Investigations reveal that BadIIS has been under active development since at least September 2021, with the most recent compiled sample observed on January 6, 2026. The malware undergoes rapid iterative updates, features branching, and incorporates reactive evasion tactics specifically designed to bypass security vendors like Norton. This continuous maintenance underscores the threat actor’s commitment to evolving the malware and its capabilities.

The individual behind this campaign operates under the alias “lwxat,” a handle consistently found within the malware’s builder tool, authentication mechanisms, and even in live HTTP user-agent strings during active command-and-control (C2) communications. Further PDB path artifacts suggest customized builds tailored for specific clients, reinforcing the MaaS business model where different customers receive bespoke versions of the malware.

BadIIS’s Hijacking Capabilities

The core of BadIIS’s functionality lies in its specialized builder tool. Threat actors leverage this tool to generate custom configuration files, JavaScript redirectors, and PHP backlink scripts, which are then injected into the BadIIS binaries. The builder offers four primary capabilities:

  • Traffic Redirection: Forcibly sends legitimate users to illicit sites, such as illegal gambling platforms and adult content websites, by injecting JavaScript-based redirectors into the victim’s browser session.
  • Reverse Proxying: Manipulates search engine crawlers by acting as a reverse proxy. It fetches illicit content from the attacker’s C2 backend and serves it as if it originated from the legitimate, compromised website.
  • Full Content Hijacking: Allows threat actors to completely take over the compromised website’s content, including configuring the percentage of traffic affected and dynamically pulling malicious title, description, and keyword metadata from a remote URL.
  • Backlink Injection: Inserts both internal and external backlinks for malicious SEO fraud, boosting the ranking of attacker-controlled sites.

A MaaS Ecosystem Built for Scale

Beyond the primary BadIIS binary, Cisco Talos uncovered a comprehensive suite of auxiliary tools developed by the same author. These include service-based installers, dropper components, and robust persistence mechanisms. These tools ensure that BadIIS automatically reactivates itself whenever a compromised IIS server restarts, significantly complicating manual cleanup efforts. The malware also employs custom Base64 encoding and single-byte XOR obfuscation to hide its C2 server addresses from security scanners.

One of the persistence tools masquerades as legitimate Windows services, such as FaxService or AudiosService, to avoid detection during routine security checks. Another tool functions as a module initialization dropper, packaging the malicious DLL payloads within a standalone executable named “IIS32” and “IIS64” within its resources. Collectively, these components form a modular and scalable ecosystem designed for sustained access and continuous illicit revenue generation.

What You Should Do

  • Regularly Audit IIS Modules: System administrators should frequently inspect installed IIS modules and review the applicationHost.config file for any unfamiliar or unauthorized entries.
  • Monitor Network Connections: Implement robust monitoring for unexpected outbound connections originating from web servers.
  • Update Security Products: Ensure all security products, including antivirus and intrusion detection systems, are kept up-to-date with the latest threat intelligence and BadIIS-specific signatures (e.g., ClamAV signatures Win.Malware.BadIIS-10069981-0, Win.Malware.BadIIS-10069988-0, Win.Malware.BadIIS-10069984-0, Win.Malware.BadIIS-10069985-0; SNORT rules 1:66400, 1:66439, 1:66438 for Snort2, and 1:66400, 1:301498-1 for Snort3).
  • Look for IoCs: Scan for indicators of compromise such as the PDB string “demo.pdb”, the threat actor alias “lwxat” in builder artifacts or HTTP user-agent strings (“lwxatisme”), and file names like “IIS32” or “IIS64” within dropper resources. Also, check for the presence of fake Windows services like “Winlogin”.
  • Review PDB Paths: Be aware of developer environment artifacts in PDB paths, such as “C:UsersAdministratorDesktop build paths” or “dll-no904”, which can indicate the presence of this malware.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Drupal Core Bug CVE-2024-XXXXX Exposes Websites to Attack

Next Post

Critical Linux Kernel Vulnerability Exposes SSH Private Keys

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
August 11, 2026
Critical ClamAV Vulnerabilities Let Attackers Trigger DoS
August 11, 2026
Phishing Attack Uses SSL/TLS Certificates to Target WhatsApp Users
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us