Statistical Report on Malware Targeting Windows Web Servers in Q2 2026

Statistical Report on Malware Targeting Windows Web Servers in Q2 2026

Content


In the second quarter of 2026, the AhnLab SEcurity intelligence Center (ASEC) compiled an analysis of the current attack status for poorly managed Windows web servers and classified the malware used in these attacks. The targets were Internet Information Services (IIS) web servers and Apache Tomcat web servers running in Windows environments.

Purpose and Scope


This report provides a summary of the damage caused by attacks targeting Windows web servers identified in the second quarter of 2026, including the number of attacks, classification of malware used in attacks, web shell statistics, and actual attack cases. Malware types were classified separately, excluding web shells.

Key Statistics


Attacks on Windows web servers in the second quarter of 2026 typically began with the upload of a web shell, followed by privilege escalation, internal reconnaissance, lateral movement, remote control, cryptocurrency mining, and VPN installation. In a real-world case, evidence was found that the threat actor, believed to be UAT-8099, used LockBit 3.0 Ransomware; after uploading a web shell, they attempted to gain control and manipulate SEO using Potato, AnyDesk, GotoHTTP, LCX, the NPS client (npc.Exe), BadIIS to attempt control and SEO manipulation.

Conclusion


Attacks on Windows web servers tend to begin through file upload vulnerabilities, web framework or WAS vulnerabilities, or RCE in unpatched services.
Web shells are used as the primary means of penetration; when combined with privilege escalation tools and proxy tools, they lead to the takeover of internal networks and RDP-based remote control.
The report recommends the Vulnerability Patch, strengthening access controls such as firewalls, and updating antivirus software (V3) to the latest version.

MD5

846a797b4b1d5263e3590972fd4932d0
9d6ceaf548bacb6a160373526d985670
ae8acf66bfe3a44148964048b826d005
f10705e4ab152e53ef2034701a3aef34
fcfbb0d2c777f3309fcfa7701c913cee
URL

http[:]//203[.]227[.]44[.]104[:]99/AnyDesk[.]exe
http[:]//203[.]227[.]44[.]104[:]99/hi[.]exe
http[:]//203[.]227[.]44[.]104[:]99/sinlcx[.]exe
IP

203[.]227[.]44[.]104
221[.]128[.]249[.]12
45[.]200[.]17[.]212