⤷ Title: Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:26:42 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:26:42 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Machine Key #China APT #IIS Backdoor #Kernel Rootkit #SEO Cloaking #TOLLBOOTH #Web Shell
Daily CyberSecurity
Chinese Hackers Exploit Exposed ASP.NET Keys to Deploy TOLLBOOTH IIS Backdoor and Kernel Rootkit
Elastic exposed Chinese threat actors exploiting public ASP.NET machine keys to deploy TOLLBOOTH IIS backdoor and HIDDENDRIVER kernel rootkit. The malware performs stealthy SEO cloaking.