None
EN
BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
Cybersecurity researchers are calling attention to a search engine optimization (SEO) poisoning campaign likely undertaken by a Chinese-speaking threat actor using a malware called BadIIS in attacks targeting East and Southeast Asia, particularly with a focus on Vietnam.
The threat actor has been found to share infrastructure and architectural overlaps with an entity referred to as Group 9 by ESET and DragonRank.
"To perform SEO poisoning, attackers manipulate search engine results to trick people into visiting unexpected or unwanted websites (e.g., gambling and porn websites) for financial gain," security researcher Yoav Zemah said.
BadIIS is designed to intercept and modify incoming HTTP web traffic with the end goal of serving malicious content to site visitors using legitimate compromised servers.
"The lure is built by attackers feeding manipulated content to search engine crawlers.
['traffic'
'site'
'malware'
'content'
'spreads'
'badiis'
'unit'
'engine'
'actor'
'seo'
'search'
'shells'
'plants'
'threat'
'redirects'
'module'
'poisoning'
'server'
'web']