Owowa, a malicious IIS Server module used to steal Microsoft Exchange credentialsSecurity Affairs·Dec 16, 07:24 UTC · Dec 16, 2021Vulnerability42
Iran-linked APT OilRig target IIS Web Servers with new RGDoor BackdoorSecurity Affairs·Feb 4, 17:23 UTC · Feb 4, 2018Malware42
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
OilRig uses RGDoor IIS Backdoor on Targets in the Middle EastPalo Alto Unit 42·Nov 1, 11:00 UTC · Nov 1, 2018Malware42
DragonRank, a Chinese-speaking SEO manipulator service providerCisco Talos·Sep 10, 04:00 UTC · Sep 10, 2024Vulnerability42
Protecting Your Microsoft IIS Servers Against Malware AttacksThe Hacker News·Sep 8, 12:56 UTC · Sep 8, 2023Malware42
DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and EuropeThe Hacker News·Sep 11, 15:39 UTC · Sep 11, 2024Threat actor57
'SEO fraud-as-a-service' scheme hijacks Windows servers to promote gambling websitesThe Record·Sep 5, 12:04 UTC · Sep 5, 2025Phishing & fraud42
New 'SessionManager' Backdoor Targeting Microsoft Exchange Servers WorldwideInfosecurity Magazine·Jul 1, 17:30 UTC · Jul 1, 2022Malware42
Scarred Manticore Targets Middle East With Advanced MalwareInfosecurity Magazine·Oct 31, 16:30 UTC · Oct 31, 2023Malware42
Chinese Hackers Exploit T-Mobile and Other U.S. Telecoms in Broader Espionage CampaignThe Hacker News·Nov 19, 08:53 UTC · Nov 19, 2024Threat actor57
FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and LinuxThe Hacker News·Feb 28, 04:32 UTC · Feb 28, 2025Malware142
xHunt hackers hit Microsoft Exchange with two news backdoorsSecurity Affairs·Nov 9, 19:17 UTC · Nov 9, 2020Malware42
NAPLISTENER: New Malware in REF2924 Group's Arsenal for Bypassing DetectionThe Hacker News·Mar 22, 09:25 UTC · Mar 22, 2023Malware42
Velociraptor leveraged in ransomware attacksCisco Talos·Oct 9, 10:00 UTC · Oct 9, 2025RansomwareCVE-2025-6264160
Attackers compromise IIS servers by leveraging exposed ASP.NET machine keysHelp Net Security·Feb 7, 00:00 UTC · Feb 7, 2025Vulnerability42
IcePeony and Transparent Tribe Target Indian Entities with CloudThe Hacker News·Nov 11, 13:18 UTC · Nov 11, 2024VulnerabilityCVE-2022-3019047
Cryptocurrency businesses still being targeted by LazarusKaspersky Securelist·Mar 26, 14:00 UTC · Mar 26, 2019Threat actor57
North Korean Nation-State Actors Exposed in JumpCloud Hack After OPSEC BlunderThe Hacker News·Jul 26, 06:48 UTC · Jul 26, 2023Threat actor57
Several Malware Families Targeting IIS Web Servers With Malicious ModulesThe Hacker News·Aug 6, 05:11 UTC · Aug 6, 2021Malware42
Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
CISA Warns of Active Exploits Targeting Trimble Cityworks VulnerabilityThe Hacker News·Feb 12, 05:14 UTC · Feb 12, 2025Vulnerability in the wildCVE-2025-099460
North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance MalwareThe Hacker News·May 24, 06:59 UTC · May 24, 2023Malware42
Experts found a bug in the Linux version of RansomHub ransomwareSecurity Affairs·Jun 22, 09:45 UTC · Jun 22, 2024Ransomware57
RansomHub Draws in Affiliates with Multi-OS Capability and High Commission RatesRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Ransomware57
Frebniis malware abuses Microsoft IIS feature to create a backdoorSecurity Affairs·Feb 19, 20:22 UTC · Feb 19, 2023Malware42
Coinhive stops digging, but cryptomining still dominatesHelp Net Security·Apr 10, 00:00 UTC · Apr 10, 2019Vulnerability in the wildCVE-2017-7269CVE-2014-0160CVE-2014-034660
Researchers unveil February 2019's most wanted malwareHelp Net Security·Mar 12, 00:00 UTC · Mar 12, 2019MalwareCVE-2017-7269CVE-2014-0160CVE-2014-034647
Striking Oil: A Closer Look at Adversary InfrastructurePalo Alto Unit 42·Oct 15, 11:29 UTC · Oct 15, 2018Malware42
UAT-8099: Chinese-speaking cybercrime group targets highCisco Talos·Oct 2, 10:00 UTC · Oct 2, 2025Vulnerability42
Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS ServersThe Hacker News·Oct 6, 11:36 UTC · Oct 6, 2025Phishing & fraud42
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS ModuleThe Hacker News·Sep 5, 06:07 UTC · Sep 5, 2025Malware42
GhostRedirector Emerges as New ChinaInfosecurity Magazine·Sep 4, 16:45 UTC · Sep 4, 2025Vulnerability42
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched SystemsThe Hacker News·Jul 28, 15:57 UTC · Jul 28, 2025Ransomware in the wildCVE-2025-49706CVE-2025-4970460
Chinese Hackers Exploit Cityworks Flaw to Target US Local GovernmentsInfosecurity Magazine·May 26, 12:00 UTC · May 26, 2025Ransomware in the wildCVE-2025-0994160
New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican OrganizationsThe Hacker News·Mar 26, 16:59 UTC · Mar 26, 2025Malware42
Microsoft Warns of StilachiRAT: A Stealthy RAT Targeting Credentials and Crypto WalletsThe Hacker News·Mar 18, 07:00 UTC · Mar 18, 2025Malware42
U.S. CISA adds Trimble Cityworks flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 7, 21:54 UTC · Feb 7, 2025Exploit / PoC in the wildCVE-2025-099460
Iranian Cyber Group OilRig Targets Iraqi Government in Sophisticated Malware AttackThe Hacker News·Sep 12, 10:49 UTC · Sep 12, 2024Malware42
N. Korean Lazarus Group Targets Microsoft IIS Servers to Deploy Espionage MalwareThe Hacker News·May 29, 04:20 UTC · May 29, 2023Malware42