Researchers unearth Windows backdoor that’s unusually stealthy | Frebniis abuses Microsoft IIS to smuggle malicious commands in web traffic

TL;DR

Researchers have discovered a clever piece of malware that stealthily exfiltrates data and executes malicious code from Windows systems by abusing a feature in Microsoft Internet Information Services (IIS). “By hijacking and modifying IIS web server code, Frebniis is able to intercept the regular flow of HTTP request handling and look for specially formatted HTTP requests,” Symantec researchers wrote. Attackers can smuggle requests into an infected server by sending one of these requests and adding the password “7ux4398!” as a parameter

Like summarized versions? Support us on Patreon!