{"id":10635,"date":"2026-02-13T10:03:55","date_gmt":"2026-02-13T10:03:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/13\/over-1800-windows-servers-compromised-by-badiis-malware-in-large-scale-seo-poisoning-campaign\/"},"modified":"2026-02-13T10:03:55","modified_gmt":"2026-02-13T10:03:55","slug":"over-1800-windows-servers-compromised-by-badiis-malware-in-large-scale-seo-poisoning-campaign","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/13\/over-1800-windows-servers-compromised-by-badiis-malware-in-large-scale-seo-poisoning-campaign\/","title":{"rendered":"Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign"},"content":{"rendered":"<p>    Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cyber campaign has compromised over 1,800 Windows servers globally, using a potent malware strain known as BADIIS. <\/p>\n<p>This operation targets Internet Information Services (IIS) environments, transforming legitimate infrastructure into a massive network for SEO poisoning. <\/p>\n<p>By hijacking these servers, threat actors manipulate search engine results to promote illicit gambling platforms and fraudulent cryptocurrency sites, effectively monetizing compromised systems while evading traditional security defenses.<\/p>\n<p>The attack vectors used in this campaign are concerning due to their ability to affect high-profile sectors, including government agencies, educational institutions, and financial organizations across multiple countries. <\/p>\n<p>The malware integrates deeply into the web server\u2019s core processes, allowing it to intercept and modify HTTP traffic in real-time. <\/p>\n<p>This silent intrusion enables attackers to redirect specific visitors to malicious destinations without disrupting the server\u2019s normal operations for regular users or administrators.<\/p>\n<p><a href=\"https:\/\/www.elastic.co\/security-labs\/badiis-to-the-bone-new-insights-to-global-seo-poisoning-campaign\" id=\"https:\/\/www.elastic.co\/security-labs\/badiis-to-the-bone-new-insights-to-global-seo-poisoning-campaign\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Elastic Security Labs analysts identified the malware<\/a> after observing distinct post-compromise behaviors during a forensic investigation of a multinational organization. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEibAf12zGKihWWRUAuklFQGxpDizqF4_yRh0_ZMsmyKwjxPizKg-jRe6z0qAKRUgBvIinwrtB-1xzWgC1TUN6TpWWFa-SN0NdmDh5D_fnkQRcFj4aHwyzzIRBfy7_c6FcmGx8pK1TM22rvv65IjKM4b0YaBqgdASoCTZGIpuiG61_Xb419goi4_cDyYwMQ\/s16000\/Execution%2520flow%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"Execution flow (Source - Elastic)\"><figcaption class=\"wp-element-caption\">Execution flow (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p>Their research links this activity to a threat group tracked as UAT-8099, noting that the campaign exhibits a high level of operational security. <\/p>\n<p>The analysts discovered that the malware had been deployed across diverse industries, with a significant concentration of victims in the Asia-Pacific region, indicating a strategic effort to exploit regions with specific internet usage patterns.<\/p>\n<h2 class=\"wp-block-heading\" id=\"advanced-evasion-and-persistence-tactics\"><strong>Advanced Evasion and Persistence Tactics<\/strong><\/h2>\n<p>BADIIS\u2019s sophistication lies in its implementation as a malicious native <a href=\"https:\/\/cybersecuritynews.com\/badiis-malware-compromising-iis-servers\/\" id=\"91854\" target=\"_blank\" rel=\"noreferrer noopener\">IIS module<\/a>, allowing it to achieve persistence and evade detection with remarkable efficiency. <\/p>\n<p>Unlike malware running as separate processes, BADIIS loads directly into the IIS worker process, making it difficult to distinguish from legitimate server activities.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhOJ89PCQkroiNQ3K-aOi57T-ysUTUaaCGbi6PmqWBf07DBTlkt-rHCes4UYH7KmRYfyAgJkrttguFNrofxAUQEaOO2cWbj_L-C9qsVI_H2rKByvTGC-ldg8hjN26RKiktsyVgwAswdxK1YNh08Pr9iAXvDfL3L7fgBngaBWEhvCXvd9afONeU6aNLY53g\/s16000\/Inlined%2520SEO%2520backlinks%2520on%2520the%2520infected%2520page%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"Inlined SEO backlinks on the infected page (Source - Elastic)\"><figcaption class=\"wp-element-caption\">Inlined SEO backlinks on the infected page (Source \u2013 Elastic)<\/figcaption><\/figure>\n<p>Once installed, the malware employs a \u201ccontext-aware\u201d filtering mechanism to determine how to handle incoming traffic. <\/p>\n<p>It inspects the HTTP headers of every request, specifically looking for User-Agent strings associated with search engine crawlers like Googlebot. <\/p>\n<p>When a crawler is detected, BADIIS injects SEO keywords and links into the server\u2019s response, boosting the ranking of malicious sites. <\/p>\n<p>Conversely, if a system administrator or regular user accesses the site, the malware serves the clean, original content. This split-view technique ensures that the compromise remains invisible to human operators while actively <a href=\"https:\/\/cybersecuritynews.com\/hackers-attacking-it-admins-by-poisoning-seo\/\" id=\"105196\" target=\"_blank\" rel=\"noreferrer noopener\">poisoning search results<\/a>. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjJ5TcQnNMRHfq0IghVgVQz-GW5ApFPVWQMzVmShY8AjGAFzfizmCboCGtxZXiliGXaROv9tezh2EPCmblHLA1YbJLKw-pSt7b76ywbrAwyVoFOyvLzwZd7uFvz7mHjfr0Kb3vSLvkYe-6a8maU3LIbNxE2VFuReCA4NF-OZH64k8sga0Iy80AixAkTIHU\/s16000\/Redirected%2520sites%2520for%2520users%2520%28Source%2520-%2520Elastic%29.webp?ssl=1\" alt=\"Redirected sites for users (Source - Elastic)\"><figcaption class=\"wp-element-caption\">Redirected sites for users (Source \u2013 Elastic)<\/figcaption><\/figure>\n<\/div>\n<p>Furthermore, the use of direct system calls helps the malware bypass <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" id=\"16588\" target=\"_blank\" rel=\"noreferrer noopener\">endpoint detection<\/a> and response (EDR) hooks, securing its presence on the victim\u2019s machine.<\/p>\n<p>Organizations must regularly inspect installed IIS modules for unsigned or unrecognized components to detect potential infections. <\/p>\n<p>It is also essential to monitor for unexpected network connections initiated by the IIS worker process and ensure all Windows Servers are patched against known vulnerabilities to prevent future compromises.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/over-1800-windows-servers-compromised-by-badiis-malware\/\">Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/over-1800-windows-servers-compromised-by-badiis-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign A sophisticated cyber campaign has compromised over 1,800 Windows servers globally, using a potent malware strain known as BADIIS. This operation targets Internet Information Services (IIS) environments, transforming legitimate infrastructure into a massive network for SEO poisoning. By hijacking these servers, threat [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10635","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10635"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10635"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10635\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}