BadIIS is a family of malicious native modules for Microsoft Internet Information Services (IIS) on Windows web servers. It intercepts HTTP requests to monetize compromised legitimate sites through SEO fraud, including injecting attacker-controlled backlinks for search-engine crawlers, serving substituted SEO content, manipulating metadata, and redirecting selected visitors to illicit destinations. Variants can operate as reverse proxies for crawler traffic and conditionally activate based on attributes such as referrer, user agent, device type, or server network characteristics, allowing the legitimate site to appear normal to many visitors and administrators. BadIIS has been deployed after compromise of internet-facing IIS servers, often alongside web shells and other post-exploitation tooling. Associated installer and service components can register the module in the IIS request pipeline, impersonate legitimate software, obscure payloads, and restore removed modules after reboot. Commodity BadIIS variants have been used by multiple Chinese-speaking cybercrime groups, including activity tracked as UAT-8099 and REF4033, against IIS servers worldwide across government, education, healthcare, e-commerce, media, financial, and corporate sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
REF4033 is a Chinese-speaking cybercrime group responsible for a massive, coordinated SEO poisoning campaign that has compromised more than 1,800 Windows web servers worldwide using a malicious IIS module called BADIIS.
REF4033 is a Chinese-speaking cybercrime group responsible for a massive, coordinated SEO poisoning campaign that has compromised more than 1,800 Windows web servers worldwide using a malicious IIS module called BADIIS.
“Its broader toolkit includes BadIIS, QuasarRAT, Gh0stCringe, Noodle RAT, Meterpreter, and multiple members of the Potato privilege escalation family.”
Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware.
"...alters SEO rankings using web shells, open-source hacking tools, Cobalt Strike, and various BadIIS malware..."
"...alters SEO rankings using web shells, open-source hacking tools, Cobalt Strike, and various BadIIS malware..."
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack uses multiple Windows batch scripts to carry out its objectives.
the script modifies the Windows Registry and uses PowerShell to add specific directories to the Windows Defender exclusion list
uses PowerShell to add specific directories to the Windows Defender exclusion list ... reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths"
This SEO hijacking web handler silently takes over an IIS application's request pipeline via reflection.
Select instances entail the deployment of a web shell, which then paves the way for BadIIS and additional backdoors for persistent access.
The malware uses custom Base64 encoding and single-byte XOR obfuscation to conceal command-and-control server addresses from security scanners.
These installers copy the payloads straight into native IIS resource trees—impersonating trusted core processes like svchost.exe or FaxService.
During this attack, the threat actor stages three files masquerading within the System32\drivers folder.
Content Hijacking: Modifying target title, description, and keyword (TDK) metadata at a configurable percentage rate to silently piggyback off the victim site’s domain authority.
the script attempts to delete its initial staging files and scripts to cover its tracks and hinder forensic analysis
the web shell is transmitted to “up.ashx” via an HTTP POST request
Upon initialization, the module downloads content from URLs defined in its configuration... Each URL in the configuration points to a static .txt file that contains a second-stage resource.
Reverse Proxying: Intentionally intercepting search engine crawlers. When a crawler arrives, the malware acts as a reverse proxy, silently pulling black-hat SEO spam data from the attacker’s backend and rendering it to the search engine to manipulate public rankings.
enabling capabilities including traffic redirection to illicit sites, reverse proxying for search engine crawler manipulation, content hijacking, and backlink injection for malicious search engine optimization (SEO) fraud
The builder allows threat actors to input target URLs, typically JavaScript-based redirectors, designed to be injected into the victim's browser. This feature forcibly redirects legitimate user traffic to spam infrastructure, such as illegal gambling, adult content, or other malicious websites.
81 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of UAT-10147’s broader toolkit; no further functional details are provided.
A malware family installed after initial compromise, used here for persistence on IIS servers and described as a malware-as-a-service variant used by multiple Chinese-speaking cybercrime groups.
Malicious IIS component deployed on compromised Windows web servers.
A malicious IIS module/backdoor installed on compromised Windows IIS servers, associated here with search-result manipulation and persistence after initial access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.