Executive Summary
In September 2025, cybersecurity analysts uncovered a targeted campaign in East and Southeast Asia, particularly Vietnam, orchestrated by a Chinese-speaking threat actor dubbed CL-UNK-1037. Using a custom malware named BadIIS, the group launched "Operation Rewrite" by employing SEO poisoning to direct unsuspecting users to compromised websites. These sites served as a launch point for deploying BadIIS, which stealthily redirected traffic, established persistent web shells, and enabled lateral movement within infected infrastructure. The attacks leveraged trusted search results to compromise both organizations and individuals, aiming to establish long-term footholds and facilitate future malicious operations.
This incident highlights the increasing sophistication of adversaries leveraging advanced social engineering and technical tactics like SEO poisoning. The blending of supply chain and web application compromise with persistent malware demonstrates evolving TTPs that bypass conventional detection, emphasizing the urgent need for multilayered security and continuous vigilance for all organizations.
Why This Matters Now
SEO poisoning attacks are growing in frequency and sophistication, making high-traffic websites and search engine users prime targets for malware delivery. As threat actors automate these techniques, organizations must rapidly enhance their web application and search exposure defenses to prevent lateral movement and persistent access.
Attack Path Analysis
The attack began with adversaries leveraging SEO poisoning to lure victims to compromised sites, resulting in BadIIS malware delivery and web shell deployment (Initial Compromise). The attackers likely escalated privileges through web shell access or exploiting application misconfigurations (Privilege Escalation). From there, they moved laterally across cloud workloads and networks to expand their access (Lateral Movement). The command and control infrastructure was maintained via covert outbound communications facilitated by the malware’s persistence and possible evasion of egress controls (Command & Control). Exfiltration was achieved through unauthorized outbound data transfers or redirects, all while attempting to conceal their actions (Exfiltration). Finally, the attackers established persistent access for possible future disruption or further monetization, impacting system integrity and business operations (Impact).
Kill Chain Progression
Initial Compromise
Description
Attackers used SEO poisoning to direct users to malicious sites delivering BadIIS malware and planting web shells on target systems.
Related CVEs
CVE-2021-31207
CVSS 9.8An insecure deserialization vulnerability in Microsoft Exchange Server allows remote code execution.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wildCVE-2021-26855
CVSS 9.8A server-side request forgery (SSRF) vulnerability in Microsoft Exchange Server allows remote code execution.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wildCVE-2021-26857
CVSS 7.8An insecure deserialization vulnerability in Microsoft Exchange Server allows remote code execution.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wildCVE-2021-26858
CVSS 7.8A post-authentication arbitrary file write vulnerability in Microsoft Exchange Server allows remote code execution.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wildCVE-2021-27065
CVSS 7.8A post-authentication arbitrary file write vulnerability in Microsoft Exchange Server allows remote code execution.
Affected Products:
Microsoft Exchange Server – 2013, 2016, 2019
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Spearphishing Link
Command and Scripting Interpreter
Web Shell
Web Protocols
Input Capture: Keylogging
Valid Accounts
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Protection of Public-Facing Applications
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Application Security
Control ID: Pillar: Applications
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
BadIIS malware targets IIS web servers through SEO poisoning, requiring enhanced egress security, threat detection capabilities, and inline IPS protection against Chinese-speaking threat actors.
Government Administration
Operation Rewrite's focus on East/Southeast Asia creates significant risks requiring zero trust segmentation, multicloud visibility, and encrypted traffic protection for sensitive government systems.
Financial Services
Web shell implantation and traffic redirection threaten PCI compliance, demanding robust east-west traffic security, anomaly detection, and cloud firewall protection against data exfiltration.
Computer Software/Engineering
SEO poisoning campaigns targeting software companies require Kubernetes security, secure hybrid connectivity, and cloud native security fabric to protect development environments and intellectual property.
Sources
- BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shellshttps://thehackernews.com/2025/09/badiis-malware-spreads-via-seo.htmlVerified
- Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaignhttps://unit42.paloaltonetworks.com/operation-rewrite-seo-poisoning-campaign/Verified
- Researchers Warn of BadIIS Using SEO Poisoning to Redirect Users to Spam and Gambling Siteshttps://www.thaicert.or.th/en/2025/09/25/researchers-warn-of-badiis-using-seo-poisoning-to-redirect-users-to-spam-and-gambling-sites/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, internal east-west traffic controls, inline threat detection, and egress policy enforcement—enabled by CNSF and related controls—would have significantly reduced the attack surface, detected anomalous behaviors, and blocked key kill chain stages such as lateral movement, C2, and data exfiltration.
Control: Cloud Firewall (ACF)
Mitigation: Malicious inbound traffic and payload delivery attempts are detected and blocked at the cloud perimeter.
Control: Threat Detection & Anomaly Response
Mitigation: Unusual privilege escalation or suspicious process/spawn behavior is detected for rapid response.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation prevents cross-segment lateral movement by enforcing least privilege access between workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound suspicious C2 channels are blocked, throttled, or alerted upon.
Control: Encrypted Traffic (HPE) & Egress Security & Policy Enforcement
Mitigation: Sensitive data exfiltration attempts are blocked and encrypted traffic is monitored at line rate.
Persistence mechanisms and abnormal system changes are rapidly detected, enabling containment.
Impact at a Glance
Affected Business Functions
- Web Services
- Online Marketing
- Customer Support
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive customer data due to unauthorized access and redirection of web traffic.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy identity-based Zero Trust Segmentation to strictly limit workload-to-workload communications and block lateral movement.
- • Implement east-west traffic inspection and anomaly response to promptly detect web shell activity, privilege escalation, and C2 beacons.
- • Enforce granular egress controls—DNS/FQDN filtering and app-aware policy—to restrict outbound network access and detect exfiltration attempts.
- • Utilize perimeter cloud firewalls and inline IPS to block inbound exploit attempts and payload delivery at early compromise.
- • Continuously monitor for anomalous behavior, privilege misuse, and persistence using centralized visibility and automated incident response workflows.



