Executive Summary
In March 2025, cybersecurity researchers uncovered Operation Rewrite, a large-scale search engine optimization (SEO) poisoning campaign attributed to a Chinese-speaking threat actor tracked as CL-UNK-1037, with links to Group 9 and DragonRank. Attackers compromised web and application servers, deploying malicious native IIS modules dubbed "BadIIS" to intercept, modify, and proxy web traffic. By injecting SEO content and redirecting legitimate visitors, the attackers increased rankings for illicit sites, harvested sensitive data, and exfiltrated web application source code. Multiple server types—web servers, domain controllers, and high-value hosts—were compromised, indicating substantial operational impact and risk to affected organizations and individuals.
Why This Matters Now
Operation Rewrite highlights the growing trend of advanced SEO poisoning and supply-chain manipulation using server-side implants, exploiting trusted web infrastructure to silently redirect users and exfiltrate data. With attackers refining their techniques to bypass traditional defenses and target critical web assets, organizations face increasing urgency to bolster east-west traffic security, implement granular segmentation, and enhance threat detection in public-facing and internal environments.
Attack Path Analysis
Attackers initially compromised public-facing web servers, likely through exploitation of application vulnerabilities or weak credentials. Once inside, they escalated privileges to gain administrative access to IIS modules and operating system resources. The adversaries moved laterally to additional production web servers and high-value hosts, deploying web shells and further implants. Subsequently, they established persistent command and control channels via malicious IIS modules communicating with external C2 servers. Source code and other sensitive files were exfiltrated as compressed archives over HTTP. Ultimately, the attackers modified legitimate web content, enabling widespread SEO poisoning and user redirection for financial gain and reputational harm.
Kill Chain Progression
Initial Compromise
Description
Attackers gained access to public-facing web servers by exploiting vulnerabilities or misconfigurations, enabling upload of web shells and malicious modules.
Related CVEs
CVE-2019-18935
CVSS 9.8A .NET deserialization vulnerability in Telerik UI for ASP.NET AJAX allows remote code execution on affected IIS servers.
Affected Products:
Progress Software Telerik UI for ASP.NET AJAX – 2013.2.717
Exploit Status:
exploited in the wildCVE-2017-11357
CVSS 7.5A vulnerability in Telerik UI for ASP.NET AJAX allows remote attackers to obtain encryption keys, facilitating further attacks.
Affected Products:
Progress Software Telerik UI for ASP.NET AJAX – 2013.2.717
Exploit Status:
exploited in the wildCVE-2017-11317
CVSS 7.5A vulnerability in Telerik UI for ASP.NET AJAX allows remote attackers to decrypt encrypted data, leading to information disclosure.
Affected Products:
Progress Software Telerik UI for ASP.NET AJAX – 2013.2.717
Exploit Status:
exploited in the wildCVE-2017-9248
CVSS 9.8A vulnerability in Telerik UI for ASP.NET AJAX allows remote attackers to execute arbitrary code via deserialization.
Affected Products:
Progress Software Telerik UI for ASP.NET AJAX – 2013.2.717
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
IIS Components (Server Software Component)
Command and Scripting Interpreter: JavaScript/JScript
Application Layer Protocol: Web Protocols
Spearphishing Link
Obfuscated Files or Information
Masquerading
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Change and Tamper Detection Mechanisms
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Measures
Control ID: Art. 9, Par. 2
CISA Zero Trust Maturity Model 2.0 – Ongoing Resource and Integrity Monitoring
Control ID: Identity Pillar: Continuous Monitoring
NIS2 Directive – Incident Prevention and Detection
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
High-value targets for SEO poisoning campaigns compromising official websites to redirect citizens to malicious content, undermining public trust and service delivery.
Higher Education/Acadamia
Educational institutions face reputation damage from compromised websites serving gambling/pornographic content through IIS module attacks targeting established domain authority.
Computer Software/Engineering
Software companies running IIS web servers vulnerable to BadIIS module injection requiring enhanced egress security and threat detection capabilities.
Financial Services
Banking websites targeted for domain reputation hijacking to redirect customers to fraudulent betting sites, necessitating robust web application security controls.
Sources
- Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaignhttps://unit42.paloaltonetworks.com/operation-rewrite-seo-poisoning-campaign/Verified
- Threat Actors Exploit Telerik Vulnerability in U.S. Government IIS Serverhttps://www.cisa.gov/sites/default/files/2023-03/aa23-074a-threat-actors-exploit-telerik-vulnerability-in-us-government-iis-server_1.pdfVerified
- ESET Threat Report T2 2021https://web-assets.esetstatic.com/wls/2021/09/eset_threat_report_t22021.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, microsegmentation, and egress policy enforcement would have significantly limited attacker movement, reduced access to high-value assets, and prevented exfiltration and C2 communications. Runtime threat detection, network-level visibility, and inline enforcement could have detected or blocked malicious modules, web shells, and data leakage early in the kill chain.
Control: Cloud Firewall (ACF)
Mitigation: Blocked exploit delivery and unauthorized inbound connections.
Control: Zero Trust Segmentation
Mitigation: Limited attacker ability to access privileged assets and services.
Control: East-West Traffic Security
Mitigation: Detected and contained unauthorized internal communication.
Control: Egress Security & Policy Enforcement
Mitigation: Blocked unauthorized outbound C2 communications.
Control: Threat Detection & Anomaly Response
Mitigation: Detected and alerted on anomalous data transfer outflows.
Prevented or rapidly detected malicious web content manipulation.
Impact at a Glance
Affected Business Functions
- Web Hosting
- Online Marketing
- Customer Engagement
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of sensitive customer data and website source code due to unauthorized access and exfiltration by attackers.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation and least-privilege policies across all web applications and cloud workloads to prevent lateral movement.
- • Implement robust egress filtering and FQDN-based policy controls to disrupt C2 communications and exfiltration attempts.
- • Leverage threat detection and continuous anomaly response to rapidly identify unexpected server behaviors and data flows.
- • Deploy cloud-native firewalling and runtime inspection to detect and block web shell and malware implant activity at the perimeter and workload levels.
- • Centralize visibility and policy management in hybrid/multicloud environments for rapid detection, response, and recovery from advanced SEO poisoning and web supply chain threats.



