June Huntress post-breach analysis of Windows server persistence, BadIIS, and miner deployment
Technical Analysis
Summary
Hide ▲
Show ▼
A June Huntress investigation reconstructed an attacker’s post-breach hardening on a single Windows server, showing how a compromise can turn into long-lived access and evasion. Initial access came through a SQL injection flaw on a web page tied to Microsoft SQL Server. After entry, the attacker performed service recon, enabled Remote Desktop, created a local Administrator account, and disabled Windows Defender. They then installed BadIIS IIS add-ons and a cryptocurrency miner, layering persistence and monetization on the same host.
Related Happenings
Apache Tomcat Oracle SQL injection flaw under active exploitation
Vulnerability
H score49
First: 05.08.2026 22:55
Last: 05.08.2026 22:55
Sources 1
About this happening:
SQL injection in a public-facing Java application running Apache Tomcat let attackers reach an Oracle database and load the khunt toolkit as database-stored Java...
Apache Tomcat Oracle SQL injection flaw under active exploitation
VulnerabilityAbout this happening: SQL injection in a public-facing Java application running Apache Tomcat let attackers reach an Oracle database and load the khunt toolkit as database-stored Java...
IT services firm in South Asia data exposed after Spirals breach
Data Leak
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...
IT services firm in South Asia data exposed after Spirals breach
Data LeakAbout this happening: Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...
IT services firm in South Asia hit by ransomware attack
Incident
H score31
First: 16.07.2026 13:00
Last: 16.07.2026 13:00
Sources 1
About this happening:
The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
IT services firm in South Asia hit by ransomware attack
IncidentAbout this happening: The IT services firm in South Asia suffered a Spirals ransomware intrusion that moved from initial access to data theft and encryption in less than 24 hours, putti...
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentAbout this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
FamousSparrow Azerbaijanian oil-and-gas targeting campaign
Campaign
H score32
First: 13.05.2026 16:00
Last: 13.05.2026 16:00
Sources 1
About this happening:
The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...
FamousSparrow Azerbaijanian oil-and-gas targeting campaign
CampaignAbout this happening: The China-linked FamousSparrow group ran a targeted cyberespionage campaign against an Azerbaijanian oil-and-gas company in the South Caucasus, highlighting a new...
Timeline
-
30.07.2026 17:01 2 articles · 8d ago
June Huntress post-breach analysis of Windows server persistence, BadIIS, and miner deployment
Initial DisclosureInitial access came through an unvalidated web input field that enabled SQL injection and access to the underlying Windows machine. The first observed actions were light reconnaissance and service discovery before persistence and evasion changes began.
Show sources
- After the Break-In: What Attackers Do Once They're Already Inside — www.bleepingcomputer.com — 30.07.2026 17:01
- After the Break-In: What Attackers Do Once They're Already Inside — www.bleepingcomputer.com — 30.07.2026 17:01