OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
Protecting Your Microsoft IIS Servers Against Malware AttacksThe Hacker News·Sep 8, 12:56 UTC · Sep 8, 2023Malware42
The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefactKaspersky Securelist·Jun 30, 08:00 UTC · Jun 30, 2022Malware42
Several Malware Families Targeting IIS Web Servers With Malicious ModulesThe Hacker News·Aug 6, 05:11 UTC · Aug 6, 2021Malware42
Hackers are abusing IIS extensions to establish covert backdoorsSecurity Affairs·Jul 27, 20:18 UTC · Jul 27, 2022Malware55
Owowa: the add-on that turns your OWA into a credential stealer and remote access panelKaspersky Securelist·Dec 14, 10:00 UTC · Dec 14, 2021Malware30
Frebniis malware abuses Microsoft IIS feature to create a backdoorSecurity Affairs·Feb 19, 20:22 UTC · Feb 19, 2023Malware42
China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO MalwareThe Hacker News·Feb 20, 11:40 UTC · Feb 20, 2026Malware30
BadIIS Malware Exploits IIS Servers for SEO FraudInfosecurity Magazine·Feb 10, 17:15 UTC · Feb 10, 2025Malware55
Iran-linked APT OilRig target IIS Web Servers with new RGDoor BackdoorSecurity Affairs·Feb 4, 17:23 UTC · Feb 4, 2018Malware42
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell FrameworkThe Hacker News·Jun 5, 13:49 UTC · Jun 5, 2026Malware30
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS ModuleThe Hacker News·Sep 5, 06:07 UTC · Sep 5, 2025Malware42
Frebniis Malware Exploits Microsoft IIS FeatureInfosecurity Magazine·Feb 20, 16:00 UTC · Feb 20, 2023Malware55
SessionManager Backdoor employed in attacks on Microsoft IIS serversSecurity Affairs·Jul 1, 20:24 UTC · Jul 1, 2022Malware42
Hackers Using Malicious IIS Server Module to Steal Microsoft Exchange CredentialsThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2021Malware42
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by ChineseCisco Talos·May 19, 10:00 UTC · May 19, 2026Malware130
Massive online crime crackdown leads to 1,000 arrestsHelp Net Security·Nov 30, 00:00 UTC · Nov 30, 2021Malware55
DragonRank Exploits IIS Servers with BadIIS Malware for SEO Fraud and Gambling RedirectsThe Hacker News·Feb 10, 15:08 UTC · Feb 10, 2025Malware30
Africa Cyber Surge II law enforcement operation has led to the arrest of 14 suspectsSecurity Affairs·Aug 18, 15:55 UTC · Aug 18, 2023Malware30
New 'SessionManager' Backdoor Targeting Microsoft IIS Servers in the WildThe Hacker News·Jul 1, 15:53 UTC · Jul 1, 2022Malware142
N. Korean Lazarus Group Targets Microsoft IIS Servers to Deploy Espionage MalwareThe Hacker News·May 29, 04:20 UTC · May 29, 2023Malware42
APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaignKaspersky Securelist·Mar 30, 10:00 UTC · Mar 30, 2021Malware42
Dissecting UAT-8099: New persistence mechanisms and regional focusCisco Talos·Jan 29, 11:00 UTC · Jan 29, 2026Malware55
Shamoon The Wiper: Further Details (Part II)Kaspersky Securelist·Sep 11, 01:08 UTC · Sep 11, 2012Malware30
China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT MalwareThe Hacker News·Dec 19, 04:48 UTC · Dec 19, 2025Malware42
Phantom Taurus: New China-Linked Hacker Group Hits Governments With Stealth MalwareThe Hacker News·Oct 1, 06:55 UTC · Oct 1, 2025Malware55
BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web ShellsThe Hacker News·Sep 23, 08:13 UTC · Sep 23, 2025Malware30
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
China-linked APT Phantom Taurus uses Net-Star malware in espionage campaigns against key sectorsSecurity Affairs·Oct 2, 07:40 UTC · Oct 2, 2025Malware42
We can try to bridge the cybersecurity skills gap, but that doesn’t necessarily mean more jobs for defendersCisco Talos·Sep 12, 18:00 UTC · Sep 12, 2024Malware55
Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware AttackThe Hacker News·Sep 12, 10:49 UTC · Sep 12, 2024Malware42
New 'SessionManager' Backdoor Targeting Microsoft Exchange Servers WorldwideInfosecurity Magazine·Jul 1, 17:30 UTC · Jul 1, 2022Malware42
Interpol Arrests Over 1,000 Cyber Criminals From 20 Countries; Seizes $27 MillionThe Hacker News·Nov 29, 07:57 UTC · Nov 29, 2021Malware30
Friday Squid Blogging: Why Mexican Jumbo Squid Populations Have DeclinedSchneier on Security·Jan 29, 08:03 UTC · Jan 29, 2020Malware55
How much cost a StingRay? Surveillance is a profitable businessSecurity Affairs·Oct 8, 19:18 UTC · Oct 8, 2017Malware30
New China-Aligned Hackers Hit State and Telecom SectorsInfosecurity Magazine·Oct 1, 11:00 UTC · Oct 1, 2025Malware55
Iranian Hackers Maintain 2-Year Access to Middle East CNI via VPN Flaws and MalwareThe Hacker News·Jul 29, 09:05 UTC · Jul 29, 2025MalwareCVE-2023-38950CVE-2023-38951CVE-2023-3895260
GhostContainer backdoor for Exchange serversKaspersky Securelist·Jul 17, 08:00 UTC · Jul 17, 2025MalwareCVE-2020-068847