logo

Chinese Threat Actors Exploit High-Value IIS Servers to Manipulate Search Rankings

ID: 1a9e15c6-bb7b-5167-9c59-08bde23b2738

STIX ID: report--1a9e15c6-bb7b-5167-9c59-08bde23b2738

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2025-10-03

Date Updated: 2026-04-13

Author: AnuPriya

...
...

Cisco Talos warns that UAT-8099, a Chinese-speaking cybercriminal group, has been mass-scanning for and compromising misconfigured IIS servers across multiple countries since April 2025, deploying BadIIS web shells and Cobalt Strike to gain persistence, create/privilege-escalate accounts, dump credentials, exfiltrate sensitive data, and monetize access via SEO fraud that redirects search traffic to gambling and ad sites; Talos recommends patching IIS, restricting uploads, enforcing strong authentication and monitoring for web-shell and Cobalt Strike activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.