Cyber Security News

Hackers Compromise IIS Servers to add Expired Certificate Notification that Installs Malware

The threat actor always compromises the Windows IIS server, which they have to add with the expired certificate notification page, which always prompts visitors to download the malicious fake installer.

Internet Information Service included all the Windows versions from Windows 2000 to server 2003.

The message indicates the malicious certificate expiration error that detects the potential security risk. This has not been extended in the transition. It gets the security certificate that allows this to succeed.

When it is a Malwarebytes Threat Intelligence security researchers have to observe where the malware gets installed via fake update and the Digicert certificate signs this.

In this, the payload got dropped with the infected system where TVRAT is designed to provide the operator with full remote access with an infected host. Once it gets to deploy in the infected device, this malware will silently install the TeamViewer remote control software.

Teamviewer on the infected cost

After it gets launched the Team Viewer server can reach the command-and-control (C2) and the attacker knows that they can remotely control with the newly compromised computer. TVRAT firstly gets surfaced in 2013, where it got delivered via spam and was campaigning with the malicious attachment, which got targeted with the office macros.

About IIS Servers (Includes Vulnerable and Targeted)

When this method gets used, attackers compromise the IIS server, and they can have various ways to breach the Windows IIS server.

Exploit code targets the critical wormable vulnerability found in HTTP Protocol used by the Windows IIS web server and is publicly available since May.

Microsoft always patched the security flaw where the Windows Server version has to be 2004/20H2. The State-sponsor level threat actor has the leverage of various other exploits that get compromised by the internet-facing which happens mostly with the deserialization attack with a load of complete volatile.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

3 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

9 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

20 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago