Friday, May 9, 2025
Advertisements

A Sophisticated Attack Targets Windows IIS Web Servers with Malicious Modules

by Charline

A new attack campaign, discovered in February 2025, targets Windows IIS web servers with advanced malware, enabling attackers to intercept and manipulate web traffic while staying hidden. Chinese-speaking threat actors are believed to be behind the attack, focusing on South Korean web servers.

Multi-Stage Attack Process

The attack begins with exploiting poorly secured web servers. After gaining access, attackers deploy .NET loader malware as a WebShell, followed by a malicious IIS native module, “caches.dll,” which ensures persistent control over the compromised server.

Advertisements

Using legitimate IIS tools like AppCmd[.]exe, attackers ensure their malware remains undetected, loaded by IIS worker processes.

Advertisements

Malicious Activities

Once installed, the malicious module intercepts requests and manipulates data at key points in the HTTP request pipeline. It contains five malicious classes that enable attackers to execute ASP files, inject affiliate banners, redirect users, and upload files covertly.

Advertisements

Stealth and Rootkit Use

To avoid detection, attackers deploy a Chinese-language rootkit tool, “HijackDriverManager,” which hides malicious files and processes. The compromised servers also show signs of communication with Gh0st RAT, a backdoor commonly used by Chinese APT groups.

Advertisements

Mitigation Steps

Administrators should:

  • Apply the latest security patches.
  • Use behavior-based detection.
  • Monitor for unusual IIS module installations.
  • Audit server configurations and enforce strict access controls.

This campaign highlights the growing sophistication of web server attacks that leverage legitimate tools to maintain stealth and persistence.

Advertisements

You may also like

blank

At ProxyServerPro, we are dedicated to providing cutting-edge proxy solutions tailored to meet the diverse needs of businesses and individuals. Our platform offers a comprehensive range of high-performance proxies, including residential, datacenter, and mobile options, ensuring seamless browsing, data scraping, and online anonymity. With a focus on reliability, speed, and security, we empower users to navigate the digital landscape with confidence. Whether you’re managing ad verification, market research, or web automation, ProxyServerPro is your trusted partner for scalable, efficient, and secure proxy services. Explore our portal to discover how we can elevate your online experience.

© 2024 Copyright  proxyserverpro.com