Hackers Attacking IIS Servers With New Web Shell Script to Gain Complete Remotely Control

The attack emerged from a broader investigation into cyber intrusions targeting critical national infrastructure in the Middle East, where threat actors successfully deployed multiple web shell servers across compromised systems. Cybersecurity researchers have uncovered a sophisticated web shell attack targeting Microsoft Internet Information Services (IIS) servers, allowing threat actors to achieve complete remote control over compromised systems. The malicious script, identified as “UpdateChecker.aspx,” represents a significant escalation in web shell complexity, employing advanced obfuscation techniques to evade detection while maintaining persistent access to critical infrastructure. This modular architecture enables attackers to perform various malicious activities, from initial system enumeration to advanced file manipulation and command execution, all while maintaining the appearance of legitimate IIS server activity. Fortinet researchers Xiaopeng Zhang and John Simmons identified the malware during their follow-up analysis of the Middle East infrastructure breach, noting its sophisticated design and potentially devastating impact on affected organizations. Its deployment specifically targets IIS servers, which are commonly used in enterprise environments for hosting web applications and services, making it a valuable asset for threat actors seeking to establish long-term persistence within organizational networks. Functionally, the web shell organizes its capabilities into three distinct modules: Base for system reconnaissance, CommandShell for executing Windows commands with IIS privileges, and FileManager for comprehensive file system operations. Unlike traditional web shells that rely on simple PHP or ASP scripts, this variant leverages heavily obfuscated C# code embedded within an ASPX webpage file, making analysis considerably more challenging for security teams. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The web shell’s ability to operate seamlessly within Windows IIS environments while maintaining stealth through advanced obfuscation techniques makes it particularly dangerous for enterprise environments. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. The malware implements a dual-encryption scheme where the first 16 bytes contain an encrypted key using hardcoded values, followed by command data encrypted with a derived 15-byte key.

This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 29 Jul 2025 06:35:20 +0000


Cyber News related to Hackers Attacking IIS Servers With New Web Shell Script to Gain Complete Remotely Control

Hackers Attacking IIS Servers With New Web Shell Script to Gain Complete Remotely Control - The attack emerged from a broader investigation into cyber intrusions targeting critical national infrastructure in the Middle East, where threat actors successfully deployed multiple web shell servers across compromised systems. Cybersecurity ...
7 months ago Cybersecuritynews.com
New C++ Based IIS Malware With Numerous Functionalities Mimics cmd.exe To Stay Undetected - Unit 42’s analysis revealed that this new C++ based IIS malware command execution framework leverages Windows’ user-mode asynchronous procedure calls (APCs) to queue malicious tasks while maintaining the facade of legitimate cmd.exe activity. ...
11 months ago Cybersecuritynews.com
How Hackers Interrupted GTA 5 Online Gameplay on PC - Recently, a cyber-attack on Grand Theft Auto 5 Online on PC caused an interruption to thousands of players’ gameplays. The game was completely taken offline and players couldn’t even access the main gameplay menu. The attack caused an uproar ...
3 years ago Hackread.com
PoC Exploit for Critical IIS Vulnerability Released - Cybersecurity News - A recent proof-of-concept (PoC) exploit has been released for a critical vulnerability affecting Microsoft Internet Information Services (IIS). This vulnerability allows attackers to execute arbitrary code remotely, posing a significant risk to ...
6 months ago Cybersecuritynews.com CVE-2024-12345
Microsoft: Iranian hackers target researchers with new MediaPl malware - Microsoft says that a group of Iranian-backed state hackers are targeting high-profile employees of research organizations and universities across Europe and the United States in spearphishing attacks pushing new backdoor malware. The attackers, a ...
2 years ago Bleepingcomputer.com APT3 APT33
New HeadCrab Malware Hijacks 1,200 Redis Servers - Since September 2021, over a thousand vulnerable Redis servers online have been infected by a stealthy malware dubbed "HeadCrab", designed to build a botnet that mines Monero cryptocurrency. At least 1,200 servers have been infected by the HeadCrab ...
3 years ago Heimdalsecurity.com
Hackers Hijacking IIS Servers in the Wild - Recent cybersecurity investigations reveal a surge in attacks targeting Internet Information Services (IIS) servers. Hackers are exploiting vulnerabilities to hijack these servers, leveraging them for malicious activities such as cryptojacking, data ...
4 months ago Cybersecuritynews.com CVE-2023-23397 CVE-2023-28252 UNC2447
Chinese Weaver Ant hackers spied on telco network for 4 years - The threat actor appears to be more focused on network intelligence, credential harvesting, and continuous access to telecom infrastructure rather than stealing user data or financial records, which is consistent with state-sponsored ...
11 months ago Bleepingcomputer.com
18 Best Web Filtering Solutions - 2025 - Pros Cons Comprehensive content filtering.Cost can be high for full features.Malware and threat protection.Hardware-based solutions may require additional infrastructure.Easy to deploy and manage.Configuration complexity for advanced ...
1 year ago Cybersecuritynews.com
Godzilla Web Shell Attacks Stomp on Critical Apache ActiveMQ Flaw - Threat actors have unleashed a fresh wave of cyberattacks targeting a critical remote code-execution vulnerability in Apache ActiveMQ, for which the Apache Software Foundation issued a patch back in October. In many of the attacks, the adversary has ...
2 years ago Darkreading.com CVE-2023-46604
Hackers Compromised Over 1,200 Redis Database Servers - A new type of malware, designed to target vulnerable Redis servers on the internet, has been spreading rapidly since September 2021. This is a quick-spreading malware, designed to operate stealthily, that has already infiltrated over thousand ...
3 years ago Cybersecuritynews.com
Web Shells Gain Sophistication for Stealth, Persistence - Web shells, a common type of post-exploitation tool that provides easy-to-use interface through which to issue commands to a compromised server, have become increasingly popular as attackers become more cloud-aware, experts say. A Web shell known as ...
2 years ago Darkreading.com
Windows 11 April update unexpectedly creates new 'inetpub' folder - Microsoft's April 2025 Patch Tuesday updates are strangely creating an empty "inetpub" folder in the root of the C:\ drive, even on systems that do not have Internet Information Services (IIS) installed. However, this folder is now ...
10 months ago Bleepingcomputer.com
Hackers Abuse ASP Machine Keys in IIS to Bypass Security Controls - Recent cybersecurity investigations have uncovered a novel attack vector where hackers exploit ASP machine keys in Microsoft's Internet Information Services (IIS) to bypass security controls. This technique allows attackers to manipulate encrypted ...
4 months ago Cybersecuritynews.com CVE-2023-34527 Unknown
Microsoft: BlueNoroff hackers plan new crypto-theft attacks - Microsoft warns that the BlueNoroff North Korean hacking group is setting up new attack infrastructure for upcoming social engineering campaigns on LinkedIn. This financially motivated threat group also has a documented history of cryptocurrency ...
2 years ago Bleepingcomputer.com
Holiday Hackers: How to Safeguard Your Service Desk - Hackers really don't take holidays, but they will take advantage of them. Many of these cyberattacks will zero in on the service or help desk to gain entry into network systems. Recovering accounts because of forgotten passwords is one of the ...
2 years ago Bleepingcomputer.com
Hackers Attacking Windows IIS Web Server With Native Module Malware - “By installing their malicious modules on the web server, the threat actor was able to insert their affiliate links into the response values to the HTTP traffic requested from the web server,” ASEC reports shared with Cyber Security News. ...
9 months ago Cybersecuritynews.com
HeadCrab Malware Infects 1,200 Redis Servers to Mine Monero Cryptocurrency - A new stealthy malware, HeadCrab, designed to hunt down vulnerable Redis servers online has infected over a thousand of them since September 2021. Discovered by Aqua Security researchers Nitzan Yaakov and Asaf Eitani, the malware has so far ensnared ...
3 years ago Bleepingcomputer.com
Why Have Big Cybersecurity Hacks Surged in 2023? - Payments made to hackers who hold systems hostage for ransom increased by almost half through September, according to blockchain analytics firm Chainalysis Inc., totaling almost $500 million in payouts. In just the past few months, hackers have ...
2 years ago Bloomberg.com LockBit
North Korean Hackers Utilizing Credential Stuffing to Launch Cyberattacks - In an alarming new report, researchers found that North Korean-linked hackers have been using stolen passwords during cyberattacks to gain access to various government, military and financial networks. According to security experts, the creative ...
3 years ago Thehackernews.com
Echoes of SolarWinds: JetBrains TeamCity servers under attack by Russia-backed hackers - The SolarWinds hackers are infiltrating JetBrains TeamCity servers via a critical vulnerability enabling authorization bypass and arbitrary code execution, government officials warn. Russian Foreign Intelligence Service-backed threat actor CozyBear ...
2 years ago Packetstormsecurity.com CVE-2023-42793
Russian Sandworm hackers breached 11 Ukrainian telcos since May - The state-sponsored Russian hacking group tracked as 'Sandworm' has compromised eleven telecommunication service providers in Ukraine between May and September 2023. That is based on a new report by Ukraine's Computer Emergency Response Team citing ...
2 years ago Bleepingcomputer.com
New Cryptojacking Attack Targets Docker API to Create Malicious Swarm Botnet - On vulnerable endpoints, the Docker API is used to spawn an Alpine container and then retrieve an initialization shell script (init.sh) from a remote server ("solscan[.]live") that, in turn, checks if it's running as the root user and tools like curl ...
1 year ago Thehackernews.com