China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware
ID: eba4bace-e654-5057-ac18-3f028eb46609
STIX ID: report--eba4bace-e654-5057-ac18-3f028eb46609
Feed Name: The Hacker News
Cisco Talos uncovered an active campaign (late 2025–early 2026) by UAT-8099 targeting vulnerable IIS servers—particularly in Thailand and Vietnam—using web shells, PowerShell scripts, and tools like GotoHTTP to deploy BadIIS variants that perform SEO fraud. The actor creates hidden accounts (e.g., "admin$", "mysql$") and uses both malicious and legitimate utilities to evade detection and maintain long-term remote access; variants of BadIIS selectively serve malicious content to search engine crawlers and Thai-language users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
