Statistics Report on Malware Targeting Windows Web Servers in Q2 2025
Essential information
- Published
- 08/08/2025 17:08
- Modified
- 10/08/2025 21:29
- Tags
- 2025-08-08 apache tomcat iis remote code execution vulnerabilities web servers web shells windows wograt
- Related entities
- 4 observables, 3 techniques (mitre)
Description
AhnLab Security Intelligence Center analyzed attacks on Windows web servers during Q2 2025 using their Smart Defense infrastructure. The study focused on poorly managed servers, categorizing attack types and malware strains. It revealed that multiple threat actors often target vulnerable servers simultaneously, exploiting unpatched systems or misconfigurations. Attackers typically use file upload vulnerabilities to deploy web shells and execute commands, but may also exploit framework or Web Application Server weaknesses. The analysis provides detailed statistics on the number of affected systems and the frequency of attacks, offering insights into the current threat landscape for Windows-based web servers.