logo

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

ID: eba4bace-e654-5057-ac18-3f028eb46609

STIX ID: report--eba4bace-e654-5057-ac18-3f028eb46609

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-01-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cisco Talos uncovered an active campaign (late 2025–early 2026) by UAT-8099 targeting vulnerable IIS servers—particularly in Thailand and Vietnam—using web shells, PowerShell scripts, and tools like GotoHTTP to deploy BadIIS variants that perform SEO fraud. The actor creates hidden accounts (e.g., "admin$", "mysql$") and uses both malicious and legitimate utilities to evade detection and maintain long-term remote access; variants of BadIIS selectively serve malicious content to search engine crawlers and Thai-language users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.