IISpy

Aliases: BadIIS

First seen
2020-06-15 00:00:00
Malware type
webshell, spyware
Family
Malware family
Profile updated
2026-07-07 13:14:25

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:ru

Context

IISpy, also known as BadIIS, is a sophisticated webshell and spyware that targets IIS web servers. It is known for its stealth and ability to persist on compromised systems to exfiltrate sensitive data.

Detection coverage

  • 2 YARA rules

Detection rules

  • ESET_IIS_Group07_Iispy (yara-rule)
  • MALPEDIA_Win_Iispy_Auto (yara-rule)

Reports & references

  • Cisco Talos — Dragon Rank Seo Poisoning (report)
  • Cisco Talos — Uat 8099 Chinese Speaking Cybercrime Group Seo Fraud (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Iispy (report)
  • ESET — Iispy Complex Server Side Backdoor Antiforensic Features (report)

External references