UAT-8099 Hijacks Reputable Sites for SEO Fraud & Theft
ID: cab14d3e-9f6e-5737-a6fb-89f22a3594c1
STIX ID: report--cab14d3e-9f6e-5737-a6fb-89f22a3594c1
Feed Name: Dark Reading
Threat Score
Cisco Talos researchers documented UAT-8099, a cybercrime campaign that hijacks Internet-facing IIS servers at reputable organizations worldwide to install 'BadIIS' implants for SEO poisoning and redirection, deploy Cobalt Strike for persistence, and exfiltrate credentials and certificates for resale or follow-on attacks, while remaining largely invisible to site owners and users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
