logo

Dissecting UAT-8099: New persistence mechanisms and regional focus

ID: d2a11712-5a8a-5bb5-864b-701af1357a45

STIX ID: report--d2a11712-5a8a-5bb5-864b-701af1357a45

Feed Name: Cisco Talos

Threat Score
72/100

Date Published: 2026-01-29

Date Updated: 2026-04-27

Author: Joey Chen

...
...

Cisco Talos describes an active UAT-8099 campaign (Aug 2025–early 2026) that targets vulnerable IIS servers across Asia—with concentrations in Thailand and Vietnam—using web shells, PowerShell, Sharp4RemoveLog, OpenArk64, GotoHTTP and new region-specific BadIIS variants (Windows and ELF) to perform SEO fraud, maintain persistence via hidden accounts, and enable remote control; the report provides reverse-engineering details, IOCs, and detection signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.