Hackers are abusing IIS extensions to establish covert backdoorsSecurity Affairs·Jul 27, 20:18 UTC · Jul 27, 2022Malware55
Iran-linked APT OilRig target IIS Web Servers with new RGDoor BackdoorSecurity Affairs·Feb 4, 17:23 UTC · Feb 4, 2018Malware42
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell FrameworkThe Hacker News·Jun 5, 13:49 UTC · Jun 5, 2026Malware130
Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth MalwareThe Hacker News·Oct 1, 06:55 UTC · Oct 1, 2025Malware55
OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
Charming Kitten's New BellaCiao Malware Discovered in MultiThe Hacker News·Apr 27, 07:58 UTC · Apr 27, 2023Malware55
China-linked hacking group Phantom Taurus targeting embassies, foreign ministriesThe Record·Oct 1, 16:30 UTC · Oct 1, 2025Malware55
Protecting Your Microsoft IIS Servers Against Malware AttacksThe Hacker News·Sep 8, 12:56 UTC · Sep 8, 2023Malware42
We can try to bridge the cybersecurity skills gap, but that doesn’t necessarily mean more jobs for defendersCisco Talos·Sep 12, 18:00 UTC · Sep 12, 2024Malware55
New 'SessionManager' Backdoor Targeting Microsoft Exchange Servers WorldwideInfosecurity Magazine·Jul 1, 17:30 UTC · Jul 1, 2022Malware42
Scarred Manticore Targets Middle East With Advanced MalwareInfosecurity Magazine·Oct 31, 16:30 UTC · Oct 31, 2023Malware42
Banking Trojan attacks increase, large scale Ramnit campaign impacts organizations worldwideHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2018MalwareCVE-2017-7269CVE-2017-5638CVE-2014-0160+1 CVEs60
FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and LinuxThe Hacker News·Feb 28, 04:32 UTC · Feb 28, 2025Malware142
xHunt hackers hit Microsoft Exchange with two news backdoorsSecurity Affairs·Nov 9, 19:17 UTC · Nov 9, 2020Malware42
NAPLISTENER: New Malware in REF2924 Group's Arsenal for Bypassing DetectionThe Hacker News·Mar 22, 09:25 UTC · Mar 22, 2023Malware42
Several Malware Families Targeting IIS Web Servers With Malicious ModulesThe Hacker News·Aug 6, 05:11 UTC · Aug 6, 2021Malware42
North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance MalwareThe Hacker News·May 24, 06:59 UTC · May 24, 2023Malware42
Frebniis malware abuses Microsoft IIS feature to create a backdoorSecurity Affairs·Feb 19, 20:22 UTC · Feb 19, 2023Malware42
Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and MalwareThe Hacker News·Jul 29, 09:05 UTC · Jul 29, 2025MalwareCVE-2023-38950CVE-2023-38951CVE-2023-3895260
Researchers unveil February 2019's most wanted malwareHelp Net Security·Mar 12, 00:00 UTC · Mar 12, 2019MalwareCVE-2017-7269CVE-2014-0160CVE-2014-034647
Striking Oil: A Closer Look at Adversary InfrastructurePalo Alto Unit 42·Oct 15, 11:29 UTC · Oct 15, 2018Malware42
China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO MalwareThe Hacker News·Feb 20, 11:40 UTC · Feb 20, 2026Malware30
Dissecting UAT-8099: New persistence mechanisms and regional focusCisco Talos·Jan 29, 11:00 UTC · Jan 29, 2026Malware55
New China-Aligned Hackers Hit State and Telecom SectorsInfosecurity Magazine·Oct 1, 11:00 UTC · Oct 1, 2025Malware55
BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web ShellsThe Hacker News·Sep 23, 08:13 UTC · Sep 23, 2025Malware30
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS ModuleThe Hacker News·Sep 5, 06:07 UTC · Sep 5, 2025Malware42
Iran-Aligned Hacking Group Targets Middle Eastern GovernmentsInfosecurity Magazine·Jul 7, 16:00 UTC · Jul 7, 2025Malware55
New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican OrganizationsThe Hacker News·Mar 26, 16:59 UTC · Mar 26, 2025Malware42
Microsoft Warns of StilachiRAT: A Stealthy RAT Targeting Credentials and Crypto WalletsThe Hacker News·Mar 18, 07:00 UTC · Mar 18, 2025Malware42
BadIIS Malware Exploits IIS Servers for SEO FraudInfosecurity Magazine·Feb 10, 17:15 UTC · Feb 10, 2025Malware55
DragonRank Exploits IIS Servers with BadIIS Malware for SEO Fraud and Gambling RedirectsThe Hacker News·Feb 10, 15:08 UTC · Feb 10, 2025Malware30
Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware AttackThe Hacker News·Sep 12, 10:49 UTC · Sep 12, 2024Malware42
Sophisticated APT Clusters Target Southeast AsiaInfosecurity Magazine·Sep 25, 17:30 UTC · Sep 25, 2023Malware55
N. Korean Lazarus Group Targets Microsoft IIS Servers to Deploy Espionage MalwareThe Hacker News·May 29, 04:20 UTC · May 29, 2023Malware42
Frebniis Malware Exploits Microsoft IIS FeatureInfosecurity Magazine·Feb 20, 16:00 UTC · Feb 20, 2023Malware55
Hackers Using Google Ads to Spread FatalRAT Malware Disguised as Popular AppsThe Hacker News·Feb 18, 08:17 UTC · Feb 18, 2023Malware42
New 'post-exploitation' threat deployed on Microsoft Exchange servers is spotted by researchersThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Malware30
Cranefly Hackers Use Stealthy Techniques to Deliver and Control MalwareInfosecurity Magazine·Oct 28, 17:00 UTC · Oct 28, 2022Malware42
FlawedAmmy: Dangerous RAT enteres most wanted malware listHelp Net Security·Sep 21, 07:57 UTC · Sep 21, 2022MalwareCVE-2017-7269CVE-2014-0160CVE-2014-034647