TOLLBOOTH, also known as HijackServer, is a malicious Internet Information Services (IIS) module and web backdoor used to monetize compromised Windows web servers. Native and managed .NET variants, in both 32-bit and 64-bit forms, provide password-protected webshell access, operator-management functionality, command execution, and file upload capability. It performs SEO cloaking by distinguishing search-engine crawlers from ordinary visitors using request characteristics, serving keyword-stuffed content to crawlers while redirecting human visitors to attacker-selected destinations. It also supports page hijacking and link-farming operations through remotely obtained configuration and content.
TOLLBOOTH has been deployed by the Chinese-speaking REF3927 activity cluster after compromise of IIS/ASP.NET servers using publicly exposed or reused ASP.NET machine keys to forge ViewState deserialization payloads. The campaign was opportunistic and affected IIS servers globally across varied sectors. TOLLBOOTH functions as the primary persistent IIS-resident backdoor and monetization payload in these intrusions; associated activity included deployment of additional webshells, remote-management tooling, attempted credential dumping, and attempted kernel-rootkit deployment. Reinfection can occur where the exposed ASP.NET machine keys are not replaced during remediation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor was observed deploying both 32-bit and 64-bit versions of TOLLBOOTH, a malicious IIS module. Some of the malware’s key capabilities include SEO cloaking, a management channel, and a publicly accessible webshell.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IIS backdoor/module deployed using publicly exposed ASP.NET machine keys; provides SEO cloaking and web shell-like remote command execution capability.
A malicious IIS module/backdoor deployed on compromised Windows IIS servers. It supports SEO cloaking (serving keyword-stuffed/link-farm content to crawlers while redirecting human visitors), exposes a webshell endpoint (/mywebdll) with a hardcoded password, and provides operator management/debug endpoints (/health, /debug, /conf, /clean) gated by specific User-Agent strings. It dynamically retrieves per-victim configuration from attacker infrastructure and can also serve a loader that pulls an obfuscated JavaScript next stage for page hijacking/content replacement.
Malicious native and managed IIS module used to monetize compromised web servers. It provides a password-protected webshell, operator management endpoints, SEO cloaking/link-farming functionality, visitor fingerprinting and redirects to attacker-selected landing pages, and a native-module page-hijacking capability.
Windows trojan identified by unique byte patterns and strings associated with its execution and functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.