ESET disclosed a previously undocumented malware family, IIStealer (Win64/BadIIS), that compromises Microsoft IIS web servers and steals payment-card and other checkout data from e-commerce sites. The malware is implemented as a malicious native IIS module, allowing it to load inside the IIS worker process, intercept inbound HTTP POST requests sent to hardcoded checkout paths, and capture request bodies containing customer payment information and other transaction details.
Because IIStealer runs on the server after HTTPS traffic has already been decrypted, it can bypass the protection shoppers expect from SSL/TLS and harvest data directly during transaction processing. ESET observed the threat on a small number of U.S.-based IIS servers between September 2020 and January 2021, with the malware storing stolen data locally and later exfiltrating it through specially crafted HTTP requests to the compromised server; in some cases it masqueraded as a legitimate IIS component under the filename dir.dll, highlighting how native IIS extensibility can be abused for persistent, hard-to-detect server-side skimming.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
ESET disclosed and analyzed a previously undocumented IIS malware family named IIStealer, detected as Win64/BadIIS. The publication included technical details, indicators of compromise, YARA rules, and a white paper/GitHub resources.
ESET telemetry indicated the IIStealer malware targeted a small number of IIS servers in the United States and stole checkout data from compromised e-commerce websites. The observed activity occurred between September 2020 and January 2021.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcei.blackhat.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.