OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
Protecting Your Microsoft IIS Servers Against Malware AttacksThe Hacker News·Sep 8, 12:56 UTC · Sep 8, 2023Malware42
The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefactKaspersky Securelist·Jun 30, 08:00 UTC · Jun 30, 2022Malware42
Several Malware Families Targeting IIS Web Servers With Malicious ModulesThe Hacker News·Aug 6, 05:11 UTC · Aug 6, 2021Malware42
Frebniis malware abuses Microsoft IIS feature to create a backdoorSecurity Affairs·Feb 19, 20:22 UTC · Feb 19, 2023Malware42
Iran-linked APT OilRig target IIS Web Servers with new RGDoor BackdoorSecurity Affairs·Feb 4, 17:23 UTC · Feb 4, 2018Malware42
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS ModuleThe Hacker News·Sep 5, 06:07 UTC · Sep 5, 2025Malware42
SessionManager Backdoor employed in attacks on Microsoft IIS serversSecurity Affairs·Jul 1, 20:24 UTC · Jul 1, 2022Malware42
Hackers Using Malicious IIS Server Module to Steal Microsoft Exchange CredentialsThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2021Malware42
New 'SessionManager' Backdoor Targeting Microsoft IIS Servers in the WildThe Hacker News·Jul 1, 15:53 UTC · Jul 1, 2022Malware142
N. Korean Lazarus Group Targets Microsoft IIS Servers to Deploy Espionage MalwareThe Hacker News·May 29, 04:20 UTC · May 29, 2023Malware42
APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaignKaspersky Securelist·Mar 30, 10:00 UTC · Mar 30, 2021Malware42
China-Linked Ink Dragon Hacks Governments Using ShadowPad and FINALDRAFT MalwareThe Hacker News·Dec 19, 04:48 UTC · Dec 19, 2025Malware42
China-linked APT Phantom Taurus uses Net-Star malware in espionage campaigns against key sectorsSecurity Affairs·Oct 2, 07:40 UTC · Oct 2, 2025Malware42
Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware AttackThe Hacker News·Sep 12, 10:49 UTC · Sep 12, 2024Malware42
New 'SessionManager' Backdoor Targeting Microsoft Exchange Servers WorldwideInfosecurity Magazine·Jul 1, 17:30 UTC · Jul 1, 2022Malware42
GhostContainer backdoor for Exchange serversKaspersky Securelist·Jul 17, 08:00 UTC · Jul 17, 2025MalwareCVE-2020-068847
Microsoft Warns of StilachiRAT: A Stealthy RAT Targeting Credentials and Crypto WalletsThe Hacker News·Mar 18, 07:00 UTC · Mar 18, 2025Malware42
Kaspersky SOC analyzes an incident involving a web shell used as a backdoorKaspersky Securelist·Feb 28, 04:00 UTC · Feb 28, 2025Malware42
Is Gelsemium APT behind an attack in Southeast Asian Govt?Security Affairs·Sep 25, 08:43 UTC · Sep 25, 2023Malware42
Lazarus Group Targeting Microsoft Web Servers to Launch Espionage MalwareInfosecurity Magazine·May 24, 16:00 UTC · May 24, 2023Malware42
Hackers Using Google Ads to Spread FatalRAT Malware Disguised as Popular AppsThe Hacker News·Feb 18, 08:17 UTC · Feb 18, 2023Malware42
Winnti Group was planning a devastating supplySecurity Affairs·Oct 15, 06:25 UTC · Oct 15, 2019Malware42
Striking Oil: A Closer Look at Adversary InfrastructurePalo Alto Unit 42·Oct 15, 11:29 UTC · Oct 15, 2018Malware42
New Iran-Nexus Hacking Group Targets Israel Government and IT SectorsInfosecurity Magazine·Jul 6, 16:00 UTC · Jul 6, 2026Malware42
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph APIThe Hacker News·May 21, 10:41 UTC · May 21, 2026Malware142
Iran-Linked BladedFeline Hits Iraqi and Kurdish Targets with Whisper and Spearal MalwareThe Hacker News·Jun 5, 14:50 UTC · Jun 5, 2025Malware42
New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican OrganizationsThe Hacker News·Mar 26, 16:59 UTC · Mar 26, 2025Malware42
FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and LinuxThe Hacker News·Feb 28, 04:32 UTC · Feb 28, 2025Malware142
China-Backed Earth Baku Expands Cyber Attacks to Europe, Middle East, and AfricaThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2024Malware42
Earth Baku APT targets Europe, the Middle East, and AfricaSecurity Affairs·Aug 14, 17:39 UTC · Aug 14, 2024Malware42
Offensive AI: The Sine Qua Non of CybersecurityThe Hacker News·Jul 26, 11:00 UTC · Jul 26, 2024Malware42
Scarred Manticore Targets Middle East With Advanced MalwareInfosecurity Magazine·Oct 31, 16:30 UTC · Oct 31, 2023Malware42
ChamelDoH: New Linux Backdoor Utilizing DNS-overThe Hacker News·Jun 19, 08:43 UTC · Jun 19, 2023Malware42
Unveiling the Balada injector: a malware epidemic in WordPressSecurity Affairs·Jun 14, 11:13 UTC · Jun 14, 2023Malware42