REF3927, also known as RudePanda, is a Chinese-speaking, financially motivated threat cluster conducting opportunistic compromises of internet-exposed Windows IIS and ASP.NET servers. The actor abuses publicly disclosed or reused ASP.NET machine keys to forge ViewState payloads and achieve code execution through ViewState deserialization. Its operations have affected IIS servers globally across diverse sectors, consistent with automated scanning for exposed machine-key reuse rather than sector-specific targeting. Following access, REF3927 deploys Godzilla-derived webshells, uses GotoHTTP remote-management tooling, attempts account creation and credential dumping, and seeks to establish durable access. The group has also attempted to use HIDDENDRIVER, a modified Hidden rootkit-derived kernel driver that uses DKOM, kernel callbacks, filesystem filtering, and registry callbacks to conceal processes, files, directories, and registry artifacts and to restrict access to protected processes. REF3927's principal monetization payload is TOLLBOOTH, a malicious native and managed IIS module that combines a password-protected webshell and operator-management functions with SEO cloaking, link farming, page hijacking, visitor fingerprinting, and conditional redirection. TOLLBOOTH differentiates search-engine crawlers from ordinary visitors, serves crawler-oriented keyword content, and redirects human visitors to attacker-selected destinations. Incomplete remediation, particularly failure to replace exposed ASP.NET machine keys, has enabled reinfection of compromised servers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Separate intrusion cluster observed in some of the same victim environments as Jewelbug/Ink Dragon; assessed not operationally linked, but likely leveraging similar initial access methods to gain footholds.
Chinese-speaking cluster abusing publicly disclosed ASP.NET machine keys on misconfigured IIS servers to deploy the TOLLBOOTH backdoor/SEO cloaking modules, with follow-on web shell/RAT/credential theft and rootkit deployment.
Opportunistic, large-scale post-exploitation of misconfigured Windows IIS/ASP.NET servers reusing publicly exposed machine keys, leveraging ViewState deserialization for initial access, then deploying webshells (Godzilla fork), RMM (GotoHTTP), credential dumping attempts (Mimikatz), a modified 'Hidden' rootkit (HIDDENDRIVER/HIDDENCLI) for stealth, and an IIS backdoor module (TOLLBOOTH) primarily for SEO cloaking/link-farming monetization plus webshell/management endpoints.
An opportunistic, apparently Chinese-speaking intrusion cluster conducting large-scale compromise of Internet-exposed Windows IIS servers that reuse publicly disclosed ASP.NET machine keys. It uses ViewState deserialization injection for initial access, deploys webshells and remote-management tooling for persistence and interactive control, attempts credential dumping and account creation, and installs TOLLBOOTH to monetize access through SEO cloaking, link farming, traffic redirection, and page hijacking. The operators also deploy a modified Hidden rootkit to conceal processes, files, registry artifacts, and related malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.