BadIIS Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
January 29, 2026
Last Seen
May 19, 2026

BadIIS is a malware family tracked across 3 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed January 29, 2026; most recent activity May 19, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Trend Micro — www.trendmicro.com · May 19, 2026
  • From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese — Blog.Talosintelligence · May 19, 2026
  • BADIIS Malware Compromises 1,800+ Windows Servers in SEO Poisoning Attack — Cyberpress · February 13, 2026
  • Over 1,800 Windows Servers Compromised by BADIIS Malware in Large — Cybersecuritynews · February 13, 2026
  • BADIIS Malware Targets Over 1,800 Windows Servers in Massive SEO Poisoning Attack — Gbhackers · February 13, 2026
  • Vulnerable Asian IIS servers subjected to UAT-8099 targeting — Scworld · February 3, 2026
  • UAT-8099 Targets IIS in Asia with BadIIS and GotoHTTP — Socprime · February 2, 2026
  • Dissecting UAT-8099: New persistence mechanisms and regional focus — Blog.Talosintelligence · January 29, 2026

CVSS v3.1 Breakdown