Malware
IISpy
Also known as: BadIIS
Indicators of Compromise 8
MITRE ATT&CK TTPs 15
T1055 T1055.003 T1059.001 T1068 T1078 T1082 T1090 T1105 T1110 T1134 T1203 T1210 T1211 T1218 T1222
Process Injection
Defense Evasion
Thread Execution Hijacking
Defense Evasion
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Access Token Manipulation
Defense Evasion
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Defense Evasion
Defense Evasion
System Binary Proxy Execution
Defense Evasion
File and Directory Permissions Modification
Defense Evasion
Source Articles
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147, a Chinese-speaking threat actor, is deploying a new cross-platform backdoor named SPECTRE that targets both Windows and Linux systems. The implant includes advanced capabilities such as process injection, credential theft, anti-analysis routines, and EDR evasion via Bring Your Own Vulnerable Driver (BYOVD) techniques. On Linux, SPECTRE deploys a kernel rootkit called Specter, disguised as 'acpi_pad.ko', which uses ftrace-based hooking to hide processes, modules, and enable UID 0 escalation. The actor also leverages SEO fraud tools like BadIIS and a custom ASHX web handler targeting Vietnamese users, along with multiple backdoors including Meterpreter, Noodle RAT, QuasarRAT, and Gh0stCringe for persistence.
talos ·1w ago
After the Break-In: What Attackers Do Once They're Already Inside
Huntress investigated a real-world incident in June 2026 where an attacker gained initial access via a SQL injection vulnerability on a web server. After entry, the attacker conducted reconnaissance, created a backdoor user, enabled Remote Desktop, disabled Windows Defender, and deployed multiple payloads including the BadIIS malware and the XMRig cryptocurrency miner. The attacker used PowerShell scripts to maintain persistence and evade detection, highlighting the importance of not only removing malware but also identifying and patching the initial vulnerability to prevent reinfection.
bleeping-computer ·4w ago