Chinese-Speaking Threat Actor Targets IIS Servers with TOLLBOOTH

Researchers from Elastic Security Labs and Texas A&M University System Cybersecurity uncovered a widespread campaign by a Chinese-speaking threat actor exploiting misconfigured Microsoft IIS servers. The attackers deployed a malicious IIS module called TOLLBOOTH, a modified Hidden rootkit, and a Godzilla-forked webshell framework to maintain persistence and hide operations. The campaign, designated REF3927, involved deserialization attacks against ASP.NET machine keys and affected 571 servers across various industries.

Latest mentioned: 10-23
Earliest mentioned: 10-20