Cybersecuritynews BADIIS Malware Compromises 1,800+ Windows Servers for SEO Poisoning
Article Content
Browse articles
A cyber campaign has compromised over 1,800 Windows servers worldwide using BADIIS malware. This malware specifically targets Internet Information Services (IIS) environments, converting legitimate servers into a network for SEO poisoning, promoting illegal gambling sites and fraudulent cryptocurrency operations.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
Timeline
2026-02-13
BADIIS malware discovered affecting over 1,800 Windows servers
More articles in this cluster (5)
Following this threat?
Track Ref4033 and BadIIS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to enhance its attack methods, transitioning from simple scripting to semi-autonomous offensive operations.…
UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques UAT-10147, a Chinese-speaking threat actor, has been identified using the SPECTRE backdoor and a Linux rootkit to conduct sophisticated multi-platform attacks. The group employs advanced techniques such as Bring Your Own Vulnerable Driver (BYOVD) to disable endpoint detection and response (EDR) protections. Cisco…