UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
ID: 448f0e3a-05a4-55e0-a4a9-9096375af6b1
STIX ID: report--448f0e3a-05a4-55e0-a4a9-9096375af6b1
Feed Name: GBHackers
Cisco Talos attributes an active, large-scale web-server compromise campaign to a Chinese-speaking cybercrime group tracked as UAT-10147 that exploits multiple publicly disclosed RCEs (including Zimbra, AjaxPro, Nacos, and Telerik) to deploy BadIIS and other implants on Windows and Linux servers, steal data, maintain persistence, and manipulate search-engine results for financial gain; researchers uncovered an exposed attacker server with a ~170,000-URL target list and observed AI-assisted tooling used to automate exploitation, validation, reconnaissance, and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
