HXLibrary is a malicious .NET Internet Information Services (IIS) module used as a backdoor for persistent access on compromised Windows web servers. It has been associated with long-duration intrusions attributed to the Iranian threat actor commonly tracked as Lemon Sandstorm, also known as Parisite, Pioneer Kitten, and Fox Kitten, including espionage and strategic prepositioning activity against critical infrastructure in the Middle East. In observed operations, HXLibrary was installed on external-facing IIS servers as a rogue module, enabling the operator to maintain covert access and exert deep control over the host. The malware retrieves configuration data from cloud-hosted text resources to obtain command-and-control information and then communicates with attacker-controlled infrastructure through web requests. Its use alongside other custom implants such as HanifNet and NeoExpressRAT indicates a broader malware ecosystem designed for durable access, post-compromise operations, and long-term persistence inside strategically important networks. HXLibrary targets Windows systems running IIS and has been observed in campaigns affecting energy and infrastructure environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.Activities.dll ... HXLibrary
On 10 October 2023, the adversary registered a malicious IIS module on the previously uncompromised external facing IIS webserver, WEB-5... This module is a type of backdoor malware FortiGuard tracks as HXLibrary.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“Persistence was maintained through web shells and scheduled tasks …” / command lines show “schtasks /create …” and “Register-ScheduledTask …”
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom Parisite malware used to deepen access in energy and infrastructure intrusions.
Custom backdoor used to maintain long-term access in a multi-year intrusion set.
Malicious .NET IIS module that pulls C2 details from Google Docs-hosted text files and communicates with the C2 via web requests.
A malicious IIS module/backdoor enabling deep system control and persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.