TOLLBOOTH
Aliases: HijackServer IIS
- Malware type
- webshell
- Family
- Malware family
- Profile updated
- 2026-07-07 15:23:16
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
TOLLBOOTH, also known as HijackServer IIS, is a webshell deployed on IIS servers to enable unauthorized remote access and control. This malware family is used to compromise and maintain persistence on targeted systems, primarily affecting government and technology sectors.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Tollbooth_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Tollbooth (report)
- harfanglab.io — Rudepanda Owns Iis Servers Like 2003 (report)
- elastic.co — Tollbooth (report)