June Huntress post-breach analysis of Windows server persistence, BadIIS, and miner deployment
Technical Analysis
Summary
Hide ▲
Show ▼
A June Huntress investigation reconstructed an attacker’s post-breach hardening on a single Windows server, showing how a compromise can turn into long-lived access and evasion. Initial access came through a SQL injection flaw on a web page tied to Microsoft SQL Server. After entry, the attacker performed service recon, enabled Remote Desktop, created a local Administrator account, and disabled Windows Defender. They then installed BadIIS IIS add-ons and a cryptocurrency miner, layering persistence and monetization on the same host.
Related Happenings
IT services firm in South Asia data exposed after Spirals breach
Data Leak
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...
IT services firm in South Asia data exposed after Spirals breach
Data LeakAbout this happening: Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...
IT services firm in South Asia hit by ransomware attack
Incident
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
IT services firm in South Asia hit by ransomware attack
IncidentAbout this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentAbout this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
FamousSparrow Azerbaijanian oil-and-gas targeting campaign
Campaign
H score32
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...
FamousSparrow Azerbaijanian oil-and-gas targeting campaign
CampaignAbout this happening: The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
Campaign
H score37
First: 06.05.2026 16:02
Last: 06.05.2026 16:02
Sources 1
About this happening:
The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
CampaignAbout this happening: The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...
Timeline
-
30.07.2026 17:01 2 articles · 1h ago
June Huntress post-breach analysis of Windows server persistence, BadIIS, and miner deployment
Initial DisclosureInitial access came through an unvalidated web input field that enabled SQL injection and access to the underlying Windows machine. The first observed actions were light reconnaissance and service discovery before persistence and evasion changes began.
Show sources
- After the Break-In: What Attackers Do Once They're Already Inside — www.bleepingcomputer.com — 30.07.2026 17:01
- After the Break-In: What Attackers Do Once They're Already Inside — www.bleepingcomputer.com — 30.07.2026 17:01