TOLLBOOTH

Aliases: HijackServer IIS

Malware type
webshell
Family
Malware family
Profile updated
2026-07-07 15:23:16

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

TOLLBOOTH, also known as HijackServer IIS, is a webshell deployed on IIS servers to enable unauthorized remote access and control. This malware family is used to compromise and maintain persistence on targeted systems, primarily affecting government and technology sectors.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Tollbooth_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Tollbooth (report)
  • harfanglab.io — Rudepanda Owns Iis Servers Like 2003 (report)
  • elastic.co — Tollbooth (report)

External references