Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
IISpy
Malware
IISpy
Also known as:
BadIIS
Indicators of Compromise
1
Filename
XMRig
MITRE ATT&CK TTPs
1
T1059.001
PowerShell
Execution
Source Articles
After the Break-In: What Attackers Do Once They're Already Inside
Huntress investigated a real-world incident in June 2026 where an attacker gained initial access via a SQL injection vulnerability on a web server. After entry, the attacker conducted reconnaissance, created a backdoor user, enabled Remote Desktop, disabled Windows Defender, and deployed multiple payloads including the BadIIS malware and the XMRig cryptocurrency miner. The attacker used PowerShell scripts to maintain persistence and evade detection, highlighting the importance of not only removing malware but also identifying and patching the initial vulnerability to prevent reinfection.
bleeping-computer
·
2h ago