Statistical Report on Malware Targeting Windows Web Servers in Q2 2026
Content
In the second quarter of 2026, the AhnLab SEcurity intelligence Center (ASEC) compiled an analysis of the current attack status for poorly managed Windows web servers and classified the malware used in these attacks. The targets were Internet Information Services (IIS) web servers and Apache Tomcat web servers running in Windows environments.
Purpose and Scope
This report provides a summary of the damage caused by attacks targeting Windows web servers identified in the second quarter of 2026, including the number of attacks, classification of malware used in attacks, web shell statistics, and actual attack cases. Malware types were classified separately, excluding web shells.
Key Statistics
Attacks on Windows web servers in the second quarter of 2026 typically began with the upload of a web shell, followed by privilege escalation, internal reconnaissance, lateral movement, remote control, cryptocurrency mining, and VPN installation. In a real-world case, evidence was found that the threat actor, believed to be UAT-8099, used LockBit 3.0 Ransomware; after uploading a web shell, they attempted to gain control and manipulate SEO using Potato, AnyDesk, GotoHTTP, LCX, the NPS client (npc.Exe), BadIIS to attempt control and SEO manipulation.
Conclusion
Attacks on Windows web servers tend to begin through file upload vulnerabilities, web framework or WAS vulnerabilities, or RCE in unpatched services.
Web shells are used as the primary means of penetration; when combined with privilege escalation tools and proxy tools, they lead to the takeover of internal networks and RDP-based remote control.
The report recommends the Vulnerability Patch, strengthening access controls such as firewalls, and updating antivirus software (V3) to the latest version.