IIS Under Siege: UAT-8099 Deploys Region-Locked “BadIIS” & Linux Variants
ID: 02359a0b-caa3-5c1f-8c4d-86557bba0134
STIX ID: report--02359a0b-caa3-5c1f-8c4d-86557bba0134
Feed Name: securityonline.info
Threat Score
Cisco Talos reports a sophisticated, region-focused campaign by UAT-8099 targeting IIS servers across Asia using customized BadIIS malware (including a Linux ELF variant) with region‑locking, web shells, PowerShell, and GotoHTTP for persistent remote access, and notes operational overlap with the WEBJACK campaign; organizations in the region are advised to audit IIS configurations and monitor the outlined BadIIS indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
