logo

IIS Under Siege: UAT-8099 Deploys Region-Locked “BadIIS” & Linux Variants

ID: 02359a0b-caa3-5c1f-8c4d-86557bba0134

STIX ID: report--02359a0b-caa3-5c1f-8c4d-86557bba0134

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Cisco Talos reports a sophisticated, region-focused campaign by UAT-8099 targeting IIS servers across Asia using customized BadIIS malware (including a Linux ELF variant) with region‑locking, web shells, PowerShell, and GotoHTTP for persistent remote access, and notes operational overlap with the WEBJACK campaign; organizations in the region are advised to audit IIS configurations and monitor the outlined BadIIS indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.