logo

UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft

ID: 448f0e3a-05a4-55e0-a4a9-9096375af6b1

STIX ID: report--448f0e3a-05a4-55e0-a4a9-9096375af6b1

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Mayura Kathir

...
...

Cisco Talos attributes an active, large-scale web-server compromise campaign to a Chinese-speaking cybercrime group tracked as UAT-10147 that exploits multiple publicly disclosed RCEs (including Zimbra, AjaxPro, Nacos, and Telerik) to deploy BadIIS and other implants on Windows and Linux servers, steal data, maintain persistence, and manipulate search-engine results for financial gain; researchers uncovered an exposed attacker server with a ~170,000-URL target list and observed AI-assisted tooling used to automate exploitation, validation, reconnaissance, and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.