Sunday, April 13, 2025
HomeBackdoorAttackers Use Malicious IIS Extensions to Deploy Covert Backdoors into Exchange Servers

Attackers Use Malicious IIS Extensions to Deploy Covert Backdoors into Exchange Servers

Published on

SIEM as a Service

Follow Us on Google News

As opposed to web shells, malicious extensions for the IIS web server have a lower detection rate, which means attackers are increasingly using them to backdoor unpatched Exchange servers.

Since they can be hidden deep within a compromised server, and are often very difficult to detect. As they are installed in the same location as legitimate modules and use the same structure, attackers can provide themselves with the perfect and durable persistence mechanism that they need. 

Since they use the same structure as legitimate modules in order to achieve the same effect as legitimate modules. The actual mechanism used to create a backdoor is usually quite minimal and the logic is not regarded as malicious in most cases.

- Advertisement - Google News

Continued Access and built-in Capability

It is rare that attackers will use unpatched security flaws in an app that is hosted to inject such malicious extensions into a server after successfully compromising it.

These types of attacks are usually deployed after the initial payload for the attack is deployed, usually a web shell. Later on, the IIS module is deployed on the compromised server so that it can be accessed more stealthily and persistently.

Previously, Microsoft experienced the installation of custom IIS backdoors after hackers exploited the following products:-

  • ZOHO ManageEngine ADSelfService Plus
  • SolarWinds Orion

There are several things that can be harvested by malicious IIS modules once they have been deployed, and here they are listed below:- 

  • From the memory of the system, credentials are retrieved
  • Data collection from infected devices and the victims’ network
  • Payloads are delivered at a higher rate

Types of IIS Backdoors

Here below we have mentioned all the types of IIS backdoors:-

  • Web shell-based variants
  • Open-source variants
  • IIS handlers
  • Credential stealers

As a result of Kaspersky’s recent analysis of IIS extensions delivered onto Microsoft Exchange servers, it has been observed that malware performs the following actions:-

  • Execute commands
  • Steal credentials remotely

It has been at least since March 2021 that a similar piece of IIS malware has been detected in the wild, and this malware is referred to as SessionManager. 

Recommendations

It is recommended that you consider the following mitigations in order to protect your system against attacks that use malicious IIS modules:- 

  • Make sure to keep Exchange servers up to date
  • It is important to keep anti-malware and security solutions enabled at all times
  • Make sure that roles and groups that are sensitive are reviewed
  • IIS virtual directories can be restricted in order to prevent unauthorized access
  • Alerts should be prioritized based on their importance
  • Ensure that the configuration files and bin folders are in order
Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...