DragonRank is a China-linked threat cluster associated with compromises of Microsoft IIS web servers and activity overlapping the broader BadIIS-style ecosystem. Reporting places it among multiple Chinese-speaking operations that have singled out IIS infrastructure for follow-on abuse, including search-engine manipulation and related post-compromise activity. DragonRank has also been linked to PlugX usage, indicating capability beyond simple web-server monetization and suggesting overlap with tradecraft seen in China-aligned intrusion sets. DragonRank is frequently discussed alongside other IIS-focused clusters such as CL-STA-0048, GhostRedirector, Operation Rewrite, and UAT-8099, but available reporting does not support treating these as the same operator. Instead, DragonRank appears adjacent to these groups through shared targeting patterns, similar tooling families, and partially overlapping tactics. Public reporting specifically notes similarities between DragonRank-linked activity and later China-linked intrusions involving IIS exploitation, web shell deployment, DNS-based signaling or exfiltration patterns, privilege-escalation tooling from the Potato Suite, and use of PlugX in at least some related operations. The cluster is associated with compromise of internet-facing IIS servers, deployment of malicious IIS components or web shells, persistence on web infrastructure, and post-exploitation actions intended either to support espionage-oriented access or to repurpose servers for SEO fraud and traffic manipulation. In the SEO-fraud context, DragonRank has been tied to BadIIS-style malware used to hijack or redirect web traffic, inject content, and manipulate search-engine results. In adjacent reporting, DragonRank is also referenced in connection with malware and techniques more typical of China-linked intrusion activity, reinforcing assessment of a Chinese nexus. DragonRank should be treated as a distinct cluster handle rather than a fully resolved actor identity. High-confidence public facts support its characterization as a China-linked, IIS-focused threat cluster with capabilities spanning initial server compromise, persistence, defense evasion, and post-exploitation, and with observed association to both BadIIS-style web-server abuse and PlugX-related activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named China-linked operation previously observed targeting IIS servers.
China-aligned threat group observed targeting IIS web servers.
Cybercrime group using BadIIS variants to compromise web servers for search engine manipulation and SEO fraud.
Distinct but related IIS SEO-manipulation cluster in the BadIIS ecosystem; differentiated in reporting by inclusion of PlugX and other campaign-specific artifacts and patterns; sometimes discussed as a service-provider-like operation around SEO manipulation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.