Dissecting UAT-8099: New persistence mechanisms and regional focus
ID: d2a11712-5a8a-5bb5-864b-701af1357a45
STIX ID: report--d2a11712-5a8a-5bb5-864b-701af1357a45
Feed Name: Cisco Talos
Threat Score
Cisco Talos describes an active UAT-8099 campaign (Aug 2025–early 2026) that targets vulnerable IIS servers across Asia—with concentrations in Thailand and Vietnam—using web shells, PowerShell, Sharp4RemoveLog, OpenArk64, GotoHTTP and new region-specific BadIIS variants (Windows and ELF) to perform SEO fraud, maintain persistence via hidden accounts, and enable remote control; the report provides reverse-engineering details, IOCs, and detection signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
