BadIIS is a malware family tracked across 3 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed January 29, 2026; most recent activity May 19, 2026.
Since 2024, multiple Chinese-speaking cybercrime groups have been exploiting a variant of BadIIS malware to manipulate SEO and inject malicious content into compromised Internet Information Services (IIS) servers across…
A cyber campaign has compromised over 1,800 Windows servers worldwide using BADIIS malware. This malware specifically targets Internet Information Services (IIS) environments, converting legitimate servers into a…
Cisco Talos reports on the UAT-8099 campaign that has been targeting vulnerable IIS web servers across Asia since August 2025. Key affected regions include India, Pakistan, Thailand, Vietnam, and Japan, with a notable…