BadIIS is a family of malicious native modules for Microsoft Internet Information Services (IIS) web servers used to hijack web traffic and monetize compromised infrastructure through SEO fraud, traffic redirection, reverse proxying, content hijacking, and backlink injection. It is designed to load inside the IIS worker process, allowing malicious behavior to blend with normal web-server operations while maintaining access on compromised Windows servers.
BadIIS has been observed in large-scale campaigns affecting IIS servers globally, with notable concentration in the Asia-Pacific region and victims spanning government, education, finance, telecommunications, technology, and other enterprise environments. Operators use compromised servers to manipulate search-engine indexing and rankings, serve keyword-stuffed or attacker-controlled content to crawlers, and redirect human visitors to illicit destinations such as gambling, adult-content, and fraudulent cryptocurrency sites. Some variants implement split-view behavior, serving clean content to administrators and ordinary users while selectively altering responses for search-engine bots or targeted visitors.
The malware ecosystem is modular and includes builder tools, installers, droppers, and persistence components. Recovered tooling supports customized payload generation for redirection, reverse proxying, content hijacking, and internal or external backlink injection. Persistence has been achieved through malicious IIS module registration, multi-stage installers, and Windows services that restore removed modules after reboot. Variants also use obfuscation and evasion techniques, including encoded configuration data, XOR or custom Base64-style encoding, direct system calls in some samples, impersonation of legitimate services or processes, and efforts to bypass security products.
BadIIS has been linked in reporting to multiple Chinese-speaking cybercrime groups and is assessed in several investigations to be operated or distributed as a malware-as-a-service or shared commodity tool rather than being exclusive to a single actor. It has been associated with activity tracked as UAT-8099 and with broader Chinese-speaking cybercriminal SEO-poisoning operations. Distinct reporting also indicates sustained development from at least 2021 through 2026, including customer-specific builds and rapid iteration to add features, improve compatibility, and evade detection.
Observed deployment contexts indicate BadIIS is typically installed after compromise of exposed IIS infrastructure, including cases involving web shells, exploitation of vulnerable internet-facing applications, and SQL injection leading to post-compromise installation of malicious IIS modules. Once deployed, it enables long-term post-exploitation control over web traffic and supports monetization, stealthy manipulation of website content, and continued abuse of legitimate server infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...they attempted to gain control and manipulate SEO using Potato, AnyDesk, GotoHTTP, LCX, the NPS client (npc.Exe), BadIIS to attempt control and SEO manipulation.
Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware.
"...alters SEO rankings using web shells, open-source hacking tools, Cobalt Strike, and various BadIIS malware..."
"...alters SEO rankings using web shells, open-source hacking tools, Cobalt Strike, and various BadIIS malware..."
Elastic Security Labs observes large-scale SEO poisoning campaigns targeting IIS servers with BADIIS malware globally, impacting over 1,800 Windows servers.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor used appcmd.exe to install some of the known BadIIS modules ( HttpFastCgiModule.dll and HttpCgiModule.dll )
The malware uses custom Base64 encoding and single-byte XOR obfuscation to conceal command-and-control server addresses from security scanners.
These installers copy the payloads straight into native IIS resource trees—impersonating trusted core processes like svchost.exe or FaxService.
...stages three files masquerading within the System32\drivers folder... The malware uses the CopyFileA function to move the contents from the masqueraded files into the .NET directory... Techniques: Masquerading: Match Legitimate Name or Location
Content Hijacking: Modifying target title, description, and keyword (TDK) metadata at a configurable percentage rate to silently piggyback off the victim site’s domain authority.
The tool employs a custom parsing routine to segment the file based on these tags... Using this extracted data, the malware dynamically assembles command-line instructions... These fully-formed commands are then executed...
The malware uses custom Base64 encoding and single-byte XOR obfuscation to conceal command-and-control server addresses from security scanners.
Reverse Proxying: Intentionally intercepting search engine crawlers. When a crawler arrives, the malware acts as a reverse proxy, silently pulling black-hat SEO spam data from the attacker’s backend and rendering it to the search engine to manipulate public rankings.
enabling capabilities including traffic redirection to illicit sites, reverse proxying for search engine crawler manipulation, content hijacking, and backlink injection for malicious search engine optimization (SEO) fraud
The builder allows threat actors to input target URLs, typically JavaScript-based redirectors, designed to be injected into the victim's browser. This feature forcibly redirects legitimate user traffic to spam infrastructure, such as illegal gambling, adult content, or other malicious websites.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related coverage as malware used on compromised servers for SEO fraud and credential theft.
BadIIS3
A family of malicious IIS modules used for SEO fraud and web-server abuse, including traffic redirection, reverse proxying, content hijacking, and internal links injection.
Malware used on compromised IIS servers for control and SEO manipulation in the described attack chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.