IISniff

First seen
2021-08-01 00:00:00
Malware type
credential-stealer, spyware
Profile updated
2026-07-07 15:06:47

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

IISniff is a specialized malware targeting Microsoft IIS servers, designed to intercept and exfiltrate sensitive information from HTTP communications. It poses a significant risk to the confidentiality of data processed through affected servers.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Iisniff_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Iisniff (report)
  • i.blackhat.com — Us 21 Anatomy Of Native Iis Malware Wp (report)
  • ESET — Anatomy Native Iis Malware (report)
  • i.blackhat.com — Us 21 Anatomy Of Native Iis Malware (report)
  • trustwave.com — The Curious Case Of The Malicious Iis Module (report)

External references