Chinese Threat Actors Exploit High-Value IIS Servers to Manipulate Search Rankings
ID: 1a9e15c6-bb7b-5167-9c59-08bde23b2738
STIX ID: report--1a9e15c6-bb7b-5167-9c59-08bde23b2738
Feed Name: Cyber Press
Cisco Talos warns that UAT-8099, a Chinese-speaking cybercriminal group, has been mass-scanning for and compromising misconfigured IIS servers across multiple countries since April 2025, deploying BadIIS web shells and Cobalt Strike to gain persistence, create/privilege-escalate accounts, dump credentials, exfiltrate sensitive data, and monetize access via SEO fraud that redirects search traffic to gambling and ad sites; Talos recommends patching IIS, restricting uploads, enforcing strong authentication and monitoring for web-shell and Cobalt Strike activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
