UAT-8099 Exploits IIS Servers Using Web Shell Attacks

A new campaign by the threat actor UAT-8099 is targeting vulnerable Internet Information Services (IIS) servers across Asia.

Active from late 2025 through early 2026, the campaign demonstrates a significant operational shift toward highly localized attacks, explicitly focusing on victims in Thailand and Vietnam.

This activity cluster shows substantial operational overlap with the previously documented WEBJACK campaign.

Sharing critical indicators of compromise (IoCs), including malware hashes, command-and-control (C2) infrastructure, and victimology profiles.

While the actor continues to rely on web shells and legitimate utilities like SoftEther VPN, their latest tactics involve sophisticated persistence mechanisms and region-specific malware variants.

Expanded Toolset and Infection Chain

UAT-8099 gains initial access to vulnerable IIS servers and executes standard reconnaissance commands (such as whoami and tasklist).

The actor’s strategy has evolved to leverage red team tools and legitimate software to evade detection.

A key component of this campaign is the use of GotoHTTP, a remote control tool delivered via a malicious VBScript. This allows the attacker to execute scripts and maintain remote access.

The actor utilizes a suite of specialized tools to secure their foothold and erase forensic evidence:

ToolFunction
Sharp4RemoveLogA .NET utility used to clear Windows event logs to remove forensic traces.
CnCrypt ProtectAn open-source anti-rootkit that terminates security product processes via kernel-level access.
OpenArk64An open-source anti-rootkit used to terminate security product processes via kernel-level access.
GotoHTTPA legitimate remote control tool used for persistent access to the compromised server

BadIIS IISHijack: Primarily targets victims in Vietnam. This variant embeds the country code in its source code and utilizes specific directory names (e.g., VN) for installation.

BadIIS asdSearchEngine: Targets users in Thailand. It analyzes HTTP headers, specifically” User-Agent” and” Accept-Language”, to identify Thai users.

If a standard user with Thai language preferences is detected, the malware injects malicious JavaScript redirects.

To facilitate this, the threat actor utilizes distinct directory naming conventions corresponding to the target region, such as C:/Users/mssql$/Desktop/VN/ for Vietnam and C:/Users/mssql$/Desktop/newth/ for Thailand.

UAT-8099 has adapted its persistence strategies in response to security blocks. Initially, the group relied on a hidden user account named”“admin””.

Following widespread flagging of this account name by security vendors, the actor shifted to creating alternative hidden accounts, including”“mysql””,”“admin1″”,”“admin2″”, and”“power””.

Using these accounts, the actor redeploys updated BadIIS malware components, such as fasthttp.dll and cgihttp.dll.

BadIIS IISHijack version
BadIIS IISHijack version (Source: Talos Intelligence)

SEO Fraud and Template Injection

The primary objective of the BadIIS infection remains Search Engine Optimization (SEO) fraud.

The malware creates a sophisticated content-generation system that loads HTML templates to generate web pages containing spam keywords dynamically.

 SEO fraud keywords.
SEO fraud keywords. (Source: Talos Intelligence)

The malware utilizes Pinyin variable names within its templates, such as {biaoti} (title) and {guanjianci} (keywords), to populate pages with random data and promoted search terms.

The malware logic includes strict filtering to avoid breaking the infected site; it ignores static assets like .png or .css files and focuses on injection attacks on dynamic pages like .aspx and .php.

Talosintelligence also identified a Linux Executable and Linkable Format (ELF) variant of BadIIS uploaded to VirusTotal in October 2025.

This variant mirrors the functionality of the Windows versions, including proxy, injector, and SEO fraud modes, confirming theactor’ss cross-platform capabilities.

Unlike previous versions, this Linux variant specifically targets crawlers from Google, Bing, and Yahoo.

Security systems detect these threats under various signatures, including Windows.Trojan.BadIIS and Unix.Trojan.BadIIS.

Network defenders are advised to monitor for the creation of unauthorized hidden user accounts and traffic to known C2 infrastructure.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories