Elastic Security Labs and Texas A&M University System Cybersecurity identified REF3927, an opportunistic, Chinese-speaking threat actor compromising Internet-facing IIS servers whose publicly disclosed ASP.NET machine keys permit ViewState deserialization attacks. The actor deploys Godzilla-derived webshells and GotoHTTP remote-management tooling, then attempts credential dumping and account creation. Researchers identified 571 actively infected IIS servers worldwide and found no confirmed victims in mainland China.
The campaign’s main payload, TOLLBOOTH, is a malicious IIS module offering a password-protected webshell, operator-management functions, SEO cloaking, link farming, and visitor redirection for monetization. The operators also use HIDDENDRIVER, a modified Hidden rootkit, to conceal processes, files, registry artifacts, and the driver itself through low-level Windows kernel manipulation. Defenders should fully remove malware and persistence mechanisms and rotate all exposed ASP.NET machine keys with newly generated values; incomplete cleanup has enabled recurring reinfections.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs and Texas A&M University System Cybersecurity investigated REF3927 activity involving a Chinese-speaking actor exploiting ASP.NET ViewState deserialization on IIS servers whose ValidationKey and DecryptionKey values had been publicly disclosed. The opportunistic campaign used automated scanning and deployed Godzilla-derived webshells and GotoHTTP for post-compromise access.
Elastic Security published the Windows.Trojan.Tollbooth, Windows.Trojan.HiddenCli, and Windows.Trojan.HiddenDriver YARA rules covering malware used in the REF3927 campaign.
Researchers identified 571 IIS servers with active TOLLBOOTH infections across diverse industry sectors globally; no identified victim server was located in mainland China. They also observed reinfections of some remediated servers where exposed or reused ASP.NET machine keys had not been rotated.
In an observed intrusion, the actor deployed the TOLLBOOTH malicious IIS module, attempted credential dumping with Mimikatz, created an Administrator account, and attempted to deploy the HIDDENDRIVER kernel rootkit. Elastic Defend blocked the observed Mimikatz attempt and execution of TOLLBOOTH and HIDDENDRIVER.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourceasec.ahnlab.com
Open sourceuninformed.org
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.