SessionManager

First seen
2022-03-01 00:00:00
Malware type
webshell, trojan
Profile updated
2026-07-07 15:11:53

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

A malicious IIS module that allows up/download of files, remote command execution, and using the compromised server as a hop into the network behind.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Apt_Unknown_Sessionmanageriis_Strings (yara-rule)

Reports & references

  • Kaspersky — 106868 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Session Manager (report)

External references