Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A single threat actor known as ‘lwxat’ has built and commercialized a malware toolkit targeting Microsoft IIS web servers, active since at least September 2021 and observed through January 2026. The toolkit enables silent traffic hijacking, SEO fraud, and reverse proxy abuse, and is sold to multiple Chinese-speaking cybercrime groups, meaning organizations may face several independent actors deploying identical implants. Any organization running internet-facing IIS infrastructure is at risk of persistent compromise that bypasses standard web application controls.

Author

Tech Jacks Solutions