Find notable cyber news and cases, enriched with sources, timelines, and signals.

June Huntress post-breach analysis of Windows server persistence, BadIIS, and miner deployment

Technical Analysis
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

A June Huntress investigation reconstructed an attacker’s post-breach hardening on a single Windows server, showing how a compromise can turn into long-lived access and evasion. Initial access came through a SQL injection flaw on a web page tied to Microsoft SQL Server. After entry, the attacker performed service recon, enabled Remote Desktop, created a local Administrator account, and disabled Windows Defender. They then installed BadIIS IIS add-ons and a cryptocurrency miner, layering persistence and monetization on the same host.

Related Happenings

IT services firm in South Asia data exposed after Spirals breach

Data Leak
H score31 First: 16.07.2026 13:00 Last: 16.07.2026 13:00 Sources 1

About this happening: Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...

IT services firm in South Asia hit by ransomware attack

Incident
H score31 First: 16.07.2026 13:00 Last: 16.07.2026 13:00 Sources 1

About this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident
H score38 First: 16.06.2026 13:18 Last: 16.06.2026 13:18 Sources 1

About this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...

FamousSparrow Azerbaijanian oil-and-gas targeting campaign

Campaign
H score32 First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...

MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy

Campaign
H score37 First: 06.05.2026 16:02 Last: 06.05.2026 16:02 Sources 1

About this happening: The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...

Timeline

  1. 30.07.2026 17:01 2 articles · 1h ago

    June Huntress post-breach analysis of Windows server persistence, BadIIS, and miner deployment

    Initial Disclosure

    Initial access came through an unvalidated web input field that enabled SQL injection and access to the underlying Windows machine. The first observed actions were light reconnaissance and service discovery before persistence and evasion changes began.

    Show sources