BadIIS is a family of malicious native modules for Microsoft Internet Information Services (IIS) on Windows, used to monetize compromised web servers through search-engine optimization (SEO) fraud, traffic redirection, reverse proxying, content hijacking, and backlink injection. Both 32-bit and 64-bit modules exist. Registered within the IIS request-processing pipeline, the malware intercepts requests and selectively modifies responses while allowing compromised websites to appear normal to other visitors.
BadIIS distinguishes search-engine crawlers from human visitors using user-agent and referer values. It can serve attacker-controlled SEO content to crawlers, inject internal and external backlinks into legitimate pages, alter page metadata, and replace selected HTTP 404 responses with fabricated content returned as HTTP 200. Qualifying human visitors receive JavaScript-based redirects to gambling, adult-content, and cryptocurrency-fraud destinations. Variants support mobile-device, browser-language, and server-subnet filtering to tailor malicious responses and conceal activity. Remote configuration controls redirection destinations and injected content; analyzed variants use encryption or obfuscation to protect configuration and infrastructure information.
The supporting toolset includes customizable payload builders, installers, droppers, and Windows service components. Persistence mechanisms register malicious IIS modules, maintain hidden backup copies, impersonate legitimate services, and restore removed modules after server restarts. Deployment follows server compromise, including intrusions involving web shells, exploitation of public-facing application vulnerabilities, or SQL injection.
BadIIS has been used by multiple Chinese-speaking cybercrime groups, including DragonRank, REF4033/UAT-8099, and UAT-10147. One REF4033 campaign affected more than 1,800 Windows web servers worldwide, with major concentrations in China and Vietnam. Victims span government, education, healthcare, e-commerce, media, financial services, and other corporate environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
Some of the vulnerabilities weaponized by the threat actor over the course of the campaign include CVE-2022-27925 (Zimbra), CVE-2021-23758 (AjaxPro), CVE-2019-18935 (Telerik UI for ASP.NET AJAX), CVE-2021-29441, and CVE-2021-29442 (Alibaba Nacos).
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The comparison table lists DragonRank's custom implants as “Yes (BadIIS, PlugX).”
REF4033 is a Chinese-speaking cybercrime group responsible for a massive, coordinated SEO poisoning campaign that has compromised more than 1,800 Windows web servers worldwide using a malicious IIS module called BADIIS.
REF4033 is a Chinese-speaking cybercrime group responsible for a massive, coordinated SEO poisoning campaign that has compromised more than 1,800 Windows web servers worldwide using a malicious IIS module called BADIIS.
“Its broader toolkit includes BadIIS, QuasarRAT, Gh0stCringe, Noodle RAT, Meterpreter, and multiple members of the Potato privilege escalation family.”
"...alters SEO rankings using web shells, open-source hacking tools, Cobalt Strike, and various BadIIS malware..."
"...alters SEO rankings using web shells, open-source hacking tools, Cobalt Strike, and various BadIIS malware..."
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack uses multiple Windows batch scripts to carry out its objectives.
the script modifies the Windows Registry and uses PowerShell to add specific directories to the Windows Defender exclusion list
uses PowerShell to add specific directories to the Windows Defender exclusion list ... reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths"
This SEO hijacking web handler silently takes over an IIS application's request pipeline via reflection.
Select instances entail the deployment of a web shell, which then paves the way for BadIIS and additional backdoors for persistent access.
The malware uses custom Base64 encoding and single-byte XOR obfuscation to conceal command-and-control server addresses from security scanners.
These installers copy the payloads straight into native IIS resource trees—impersonating trusted core processes like svchost.exe or FaxService.
During this attack, the threat actor stages three files masquerading within the System32\drivers folder.
Content Hijacking: Modifying target title, description, and keyword (TDK) metadata at a configurable percentage rate to silently piggyback off the victim site’s domain authority.
the script attempts to delete its initial staging files and scripts to cover its tracks and hinder forensic analysis
the web shell is transmitted to “up.ashx” via an HTTP POST request
Upon initialization, the module downloads content from URLs defined in its configuration... Each URL in the configuration points to a static .txt file that contains a second-stage resource.
Reverse Proxying: Intentionally intercepting search engine crawlers. When a crawler arrives, the malware acts as a reverse proxy, silently pulling black-hat SEO spam data from the attacker’s backend and rendering it to the search engine to manipulate public rankings.
enabling capabilities including traffic redirection to illicit sites, reverse proxying for search engine crawler manipulation, content hijacking, and backlink injection for malicious search engine optimization (SEO) fraud
The builder allows threat actors to input target URLs, typically JavaScript-based redirectors, designed to be injected into the victim's browser. This feature forcibly redirects legitimate user traffic to spam infrastructure, such as illegal gambling, adult content, or other malicious websites.
81 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of UAT-10147’s broader toolkit; no further functional details are provided.
A malware family installed after initial compromise, used here for persistence on IIS servers and described as a malware-as-a-service variant used by multiple Chinese-speaking cybercrime groups.
Malicious IIS component deployed on compromised Windows web servers.
A malicious IIS module/backdoor installed on compromised Windows IIS servers, associated here with search-result manipulation and persistence after initial access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.