Researchers from Elastic Security Labs, in collaboration with Texas A&M University System (TAMUS) Cybersecurity, have uncovered a Chinese-speaking threat actor conducting a widespread campaign targeting misconfigured Microsoft IIS servers. The adversary deployed a malicious IIS module dubbed โTOLLBOOTHโ, a modified โHiddenโ rootkit, and a Godzilla-forked webshell framework to maintain persistence and hide its operations.
โThreat actors are abusing misconfigured IIS servers using publicly exposed machine keys,โ Elastic stated, adding that โthe main objective appears to be to install an IIS backdoor, called TOLLBOOTH, that includes SEO cloaking and webshell capabilities.โ
Elasticโs joint investigation revealed that the attackers exploited ASP.NET machine keysโcryptographic secrets used to protect authentication cookies and ViewState dataโthat had been carelessly published online, including on Microsoft documentation and StackOverflow.
By leveraging these publicly exposed keys, the attackers could forge serialized payloads and execute arbitrary commands through ViewState deserialization attacks.
โWe have reason to believe this is part of an opportunistic campaign targeting Windows web servers using publicly exposed machine keys,โ the researchers wrote, describing it as a large-scale, automated operation abusing shared configuration keys across geographies and industries.

Elastic and TAMUS identified the activity cluster as REF3927, connecting it to campaigns previously documented by Microsoft in February and AhnLab in April, both involving similar malware toolsets and behaviors.
Once a vulnerable IIS server was compromised, the attackers deployed webshells, including a modified Godzilla frameworkโnamed Z-Godzilla_ekpโto establish persistence and execute commands remotely. This customized variant features an AMSI bypass plugin and encrypted communications designed to mimic normal web traffic.
โThe Z-Godzilla_ekp toolkit provides operators with privilege escalation, file management, credential theft, and in-memory payload execution,โ Elastic explained. โIts traffic is AES-encrypted and embedded within HTTP POST parameters to blend into legitimate network activity.โ
When initial persistence methods failed, the threat actor deployed GotoHTTP, a legitimate Remote Monitoring and Management (RMM) tool, allowing them to control the compromised system directly through a web browser over HTTPSโbypassing conventional network detection mechanisms.
At the center of the campaign is TOLLBOOTH, a malicious IIS module capable of traffic hijacking, SEO cloaking, and command execution.
Elasticโs analysis identified both native and .NET versions of the module, each dynamically configured via JSON files retrieved from the attackerโs server at c.cseo99[.]com.
The backdoor exposes a webshell interface located at /mywebdll protected by the password hack123456!, allowing the attacker to upload files and execute commands.
TOLLBOOTH also contains multiple management endpoints (/health, /debug, /clean) for monitoring and updating the module, and a built-in SEO cloaking engine to disguise its activity.
โThe main goal of TOLLBOOTH is SEO cloaking,โ Elastic explained. โIt presents keyword-optimized content to search engine crawlers, while redirecting human visitors to fraudulent or malicious pages.โ
By differentiating between search engine bots and human visitors, the module manipulates site rankings and directs unsuspecting users to malicious domainsโan approach Elastic called a โlink farm networkโ used to propagate malware and monetize traffic across infected sites.
The attackers also deployed a kernel-mode rootkit based on the open-source project โHiddenโ, rebranded as HIDDENDRIVER.
Elasticโs reverse engineering revealed that the rootkit uses Direct Kernel Object Manipulation (DKOM) to hide processes, files, and registry keys from system monitoring tools like Process Explorer.
โThe rootkitโs InitializeStealthMode hides every artifact associated with the malware, including registry keys, the .sys driver file, and related components,โ Elastic noted.
Additionally, the userland companion app HIDDENCLI, written in Chinese, manages the rootkitโs operations, adding or removing hidden objects via IOCTL commands.
The modifications to the original โHiddenโ project included automatic process whitelisting and enhanced anti-detection logic, indicating the threat actorโs technical sophistication.
In collaboration with Validinโs global scanning infrastructure, Elastic and TAMUS identified 571 IIS servers worldwide infected with TOLLBOOTH, spanning industries from finance and logistics to government and academia.
Interestingly, no victims were located in mainland China, aligning with typical geofencing patterns used by Chinese-speaking actors to avoid domestic exposure.
โThe geographic distribution of victims notably excludes any servers within Chinaโs borders,โ the report confirmed. โThis aligns with behaviors seen in other criminal threats that implement mechanisms to avoid targeting their home countries.โ
Elastic also observed repeated reinfections, suggesting that many organizations removed the malware without addressing the underlying configuration flawโthe reuse of public machine keys.
Related Posts:
- Sophisticated IIS Malware Targets South Korean Web Servers
- Cybercriminals Mimic Slack in Sophisticated Malvertising Campaign
- Publicly Disclosed ASP.NET Machine Keys Used in Code Injection Attacks
- Web of Deceit: Unmasking the Hidden Threat of Stockpiled Domains
- Microsoft releases January Patch Tuesday to fix 56 security issues
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!