IIServerCore is a modular, fileless .NET backdoor within the NET-STAR malware suite. It executes entirely in memory in the Microsoft IIS worker-process context on compromised Windows IIS web servers. The backdoor is deployed through a web shell and uses cookie-based session management and AES-encrypted command-and-control communications. It can execute supplied code and .NET assemblies in memory, return execution output to its operators, perform file-system operations, access databases and run SQL commands, and manage web shells. IIServerCore also includes security-evasion functionality, including AMSI bypass support and timestamp modification. It has been used by the China-nexus espionage actor Phantom Taurus against government and telecommunications targets across Africa, the Middle East, and Asia, particularly organizations associated with diplomatic, geopolitical, and defense-related information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fileless modular IIS backdoor loaded via an ASPX web shell (OutlookEN.aspx) into w3wp.exe; handles sessioned C2 via cookies, decrypts commands/payloads, loads Base64-encoded .NET assemblies in memory, and provides commands for filesystem ops, SQL/database access, code execution, web shell deployment/management, and AMSI bypass, with AES-encrypted communications and timestomping support.
Fileless modular IIS backdoor (runs in w3wp.exe) loaded by an ASPX web shell; supports encrypted C2, in-memory loading/execution of .NET assemblies, filesystem ops, SQL/database access, web shell deployment/management, and includes timestomping capability (e.g., changeLastModified) and AMSI bypass functionality.
A fileless backdoor component used by NET-STAR that runs inside the IIS process and remains primarily memory-resident to reduce on-disk artifacts and hinder detection.
A fileless IIS-targeting backdoor that operates entirely in memory; can execute payloads/arguments, return results to C2, perform file and database operations, manage web shells, evade/bypass security controls, load payloads in memory, and encrypt C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.