Threat reportIntrusionTL-2026-1269
SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor, and XMRig Deployment
SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor (TL-2026-1269), also tracked as SQLi-to-BadIIS-XMRig intrusion, is a high-severity intrusion threat, first published 2026-07-13. It is attributed to UAT-8099 (China) with low confidence, affects Microsoft SQL Server, maps to 26 MITRE ATT&CK techniques (T1005, T1007, T1021), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 26MITRE ATT&CK
- Actors
- 1UAT-8099
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1269
- Threat ID
- TL-2026-1269
- Also known as
- SQLi-to-BadIIS-XMRig intrusion, Home Field Advantage intrusion
- Severity
- HIGH
- Status
- ACTIVE
- Category
- INTRUSION
- First published
- Last reviewed
- Attribution
- UAT-8099
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor
Malware and tooling: IISpy, xmrig, CnCrypt Protect, nssm.exe
How SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor works
Threat actors exploited a SQL injection flaw in an unvalidated web application input to compromise a technology-sector organization's Microsoft SQL Server, then pivoted to create a rogue admin account, enable RDP, disable Windows Defender, install malicious BadIIS IIS modules, and deploy the XMRig cryptominer via nssm.exe.
Huntress DFIR investigators observed a confirmed intrusion beginning with SQL injection against an IIS-hosted web application where user-supplied input was not validated before reaching the backend Microsoft SQL Server. The injection allowed the attacker to reach OS command execution, observed as sqlservr.exe spawning cmd.exe — consistent with abuse of MSSQL command-execution stored procedures (e.g., xp_cmdshell) reachable from an injectable query. Once on the host, the actor ran reconnaissance (tasklist /svc) and exfiltrated the output via an HTTP POST to an out-of-band interaction domain (334thribetlhkyo977gqrcht1k7bvdj2.oastify.com), a Burp Suite Collaborator/OAST-style subdomain typically used for blind SQLi/SSRF confirmation, indicating the intrusion may itself have originated from automated or semi-automated SQLi tooling reuse, or that the actor repurposed an OAST domain for DNS/HTTP beaconing and exfiltration. The actor created a new local administrator account (adminweb2$), enabled Remote Desktop Services/Terminal Services for interactive follow-on access, and disabled Windows Defender to prepare the host for further tooling. For defense evasion the actor used attrib.exe to mark dropped cryptominer files and directories as system, hidden, archive, and read-only, staging them inside a masquerading path under C:\Program Files (x86)\Microsoft\EdgeUpdate\ to blend in with a legitimate Microsoft update service. The actor installed two malicious IIS modules — HttpFastCgiModule.dll and HttpCgiModule.dll — via appcmd.exe, consistent with the BadIIS malware family (tracked publicly by Cisco Talos as used by the China-nexus group UAT-8099/REF4033 for SEO fraud, illicit traffic redirection, reverse-proxying, and content hijacking on compromised IIS servers worldwide). BadIIS integrates into the IIS request pipeline as a native module, conditionally serving keyword-stuffed content to search crawlers while redirecting real visitors to attacker-controlled destinations (gambling, adult content, crypto-phishing) and can also facilitate credential theft — giving the actor a durable, web-server-native backdoor independent of the initial SQLi foothold. For financial impact, the actor downloaded PowerShell scripts (qdcjoke1.2.ps1, c_joke1.2.ps1) and a batch launcher (qd_tjoke.bat) from a Cloudflare R2 public bucket (pub-c4c8e8c336c3429d97195076bf3bb6eb.r2.dev), executed with powershell.exe -NoLogo -NoProfile -NonInteractive -ExecutionPolicy Bypass -WindowStyle Hidden to suppress visible windows and logging prompts. These scripts staged the XMRig Monero cryptominer (delivered as xmr-1.zip) and registered it as a Windows service using nssm.exe (Non-Sucking Service Manager), a legitimate open-source service-wrapper tool abused here to auto-restart the miner process and blend in among normal Windows services. The actor additionally installed a tool referred to as "CnCrypt Protect" alongside the miner, likely intended to hinder analysis/detection of the miner binary or its configuration. No CVE was assigned by the source reporting since the vulnerability is a generic unvalidated-input SQL injection rather than a specific product flaw; no formal CVSS score was published. The concrete, actionable artifacts — the rogue account name, IIS module filenames, staging paths, script names, and the OAST/R2 delivery infrastructure — make this intrusion highly suited to detection-engineering coverage despite the lack of a CVE/CVSS anchor.
MITRE ATT&CK techniques used in TL-2026-1269
Collection
Discovery
T1007 System Service Discovery; T1057 Process Discovery; T1069 Permission Groups Discovery
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1569 System Services
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer
Privilege Escalation
Persistence
T1133 External Remote Services; T1136 Create Account; T1505 Server Software Component; T1543 Create or Modify System Process
Initial Access
T1190 Exploit Public-Facing Application
Impact
Credential Access
defense-impairment
Affected products and versions in SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor
- Microsoft — SQL Server
Vulnerable versions: unspecified/any version reachable via unvalidated application input
Fixed in: N/A — application-layer input validation fix required - Microsoft — Internet Information Services (IIS)
Vulnerable versions: unspecified version hosting the vulnerable application and IIS module pipeline
Fixed in: N/A — remove unauthorized modules; not a version-specific vulnerability
Remediation for SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor
Patches
- No vendor patch applicable — remediate the application-layer input validation defect, not a specific CVE
Immediate actions
- Validate and parameterize all SQL queries; remove any dynamic string-concatenated SQL built from unvalidated web input
- Disable or tightly restrict xp_cmdshell and other MSSQL command-execution stored procedures at the database engine level
- Audit local Administrators group membership and remove unauthorized accounts such as adminweb2$ or similarly named service-like accounts
- Disable RDP/Terminal Services on internet-facing or database-tier servers unless explicitly required and MFA-protected
- Re-enable and verify Windows Defender / EDR real-time protection and tamper protection on affected hosts
- Inspect IIS applicationHost.config / web.config for unauthorized <globalModules> or <modules> entries referencing HttpFastCgiModule.dll, HttpCgiModule.dll, or unrecognized native/managed modules; remove via appcmd.exe
- Hunt for hidden/system-attributed files under C:\Program Files (x86)\Microsoft\EdgeUpdate\ and other legitimate-looking update directories
- Identify and remove unauthorized nssm.exe-registered Windows services, especially those launching unsigned or renamed binaries
- Block outbound traffic to *.oastify.com and the identified R2 bucket subdomain at the network egress layer pending investigation
Workarounds
- Restrict application database accounts to parameterized stored procedures only; deny ad hoc SQL execution rights
- Apply Attack Surface Reduction (ASR) rules to block LOLBin abuse patterns (e.g., attrib.exe hiding files, appcmd.exe module manipulation from unexpected parent processes)
Longer-term hardening
- Deploy a web application firewall (WAF) in front of internet-facing applications with SQLi rule sets tuned to the application
- Implement least-privilege SQL service accounts and disable unnecessary MSSQL surface area (Surface Area Configuration / sp_configure)
- Deploy EDR with behavioral detection for LOLBin abuse (attrib.exe, appcmd.exe, nssm.exe) and PowerShell script-block logging
- Establish asset inventory and a formal patch/config management process for internet-facing SQL and IIS infrastructure
- Implement network segmentation so database-tier hosts cannot reach arbitrary outbound HTTP/DNS destinations
- Enforce MFA on all remote access and administrative authentication paths
Weaknesses (CWE) in SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor
Timeline of SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor
- Huntress publishes DFIR report 'Home Field Advantage: How Attackers Reshape Victim Environments' documenting the confirmed intrusion at a technology-sector organization.
- Attacker registers the XMRig miner as a resilient Windows service using nssm.exe (Non-Sucking Service Manager) to auto-restart the miner process.
- Attacker deploys XMRig cryptominer (xmr-1.zip) and installs the CnCrypt Protect anti-analysis/protection tool alongside it.
- Attacker uses attrib.exe to set cryptominer component files/directories to system, hidden, archive, read-only under a masquerading path in C:\Program Files (x86)\Microsoft\EdgeUpdate\.
- Attacker downloads PowerShell scripts qdcjoke1.2.ps1 and c_joke1.2.ps1 plus batch file qd_tjoke.bat from Cloudflare R2 bucket pub-c4c8e8c336c3429d97195076bf3bb6eb.r2.dev, executed hidden via powershell.exe with -ExecutionPolicy Bypass -WindowStyle Hidden.
- Attacker installs malicious IIS modules HttpFastCgiModule.dll and HttpCgiModule.dll via appcmd.exe, consistent with the BadIIS malware family used for SEO fraud/traffic hijacking.
- Attacker disables Windows Defender to prevent detection of subsequent tooling.
- Attacker enables Terminal Services/Remote Desktop Services to allow interactive follow-on access using the new admin account.
- Attacker creates rogue local administrator account adminweb2$ and adds it to the local Administrators group.
- Attacker runs tasklist /svc for service enumeration and exfiltrates output via HTTP POST to 334thribetlhkyo977gqrcht1k7bvdj2.oastify.com.
- Attacker exploits SQL injection in an unvalidated web application input field, gaining code execution on the backend Microsoft SQL Server (sqlservr.exe spawns cmd.exe).
Sources cited for SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor
- Home Field Advantage: How Attackers Reshape Victim Environments
- Dissecting UAT-8099: New persistence mechanisms and regional focus
- UAT-8099: Chinese-speaking cybercrime group targets high-value IIS for SEO fraud
- BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign
- China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware
- BadIIS Malware Hijacks IIS Servers to Redirect Users to Illicit Sites
- Newly-discovered threat group hijacking IIS servers for SEO fraud, warns Cisco Talos
- Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaign
- Non-Sucking Service Manager (nssm) Usage
- Sqlserver, or the Miner in the Basement
- Burp Collaborator documentation (oastify.com domain)
- Threat Advisory: XMRig Cryptomining By Way Of TeamViewer
Detection coverage for TL-2026-1269
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1269 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.