UAT-8099 is a Chinese-speaking cybercrime group primarily involved in search engine optimization (SEO) fraud and theft of high-value credentials, configuration files, and certificate data. Public reporting also describes it as China-linked or a Chinese group. Cisco Talos reported the group compromises reputable Microsoft Internet Information Services (IIS) servers for financial gain, with affected servers observed in India, Thailand, Vietnam, Canada, and Brazil, and later campaigns targeting vulnerable IIS servers across Asia with a particular focus on Thailand and Vietnam. Reported victim organizations include universities, technology companies, telecommunications providers, and other high-value organizations; broader reporting also notes government, education, and finance victims. The group’s SEO fraud redirects users to unauthorized advertisements, illegal gambling sites, fake gambling sites, and fraudulent cryptocurrency destinations, with some reporting noting a focus on mobile users. Reported initial access commonly involves weak file-upload controls, vulnerable IIS functionality, or web shell upload to IIS servers. After access, UAT-8099 has been observed using ASP.NET web shells, PowerShell, reconnaissance commands such as ipconfig, whoami, arp, and tasklist, privilege escalation, enabling or abusing the Guest account, enabling RDP, and establishing persistence through hidden local accounts including admin$, mysql$, admin1$, admin2$, and power$. The group has used RDP together with SoftEther VPN, EasyTier, FRP, and GotoHTTP for remote access and persistence. Talos also reported use of Cobalt Strike via DLL sideloading and scheduled-task persistence, ProcDump for LSASS dumping, WinRAR for staging stolen data, the Everything search tool to locate credentials and certificates, Sharp4RemoveLog to clear Windows event logs, OpenArk64 to terminate protected security processes, and CnCrypt Protect to hide malicious files and facilitate DLL redirection. In one 2026 case cited by ASEC, a threat actor believed to be UAT-8099 used LockBit 3.0 ransomware after web shell deployment, along with Potato, AnyDesk, GotoHTTP, LCX, npc.exe, and BadIIS. A core component of UAT-8099 activity is deployment of BadIIS malware on compromised IIS servers. Reporting links the group to BadIIS-based SEO poisoning, HTTP traffic interception and modification, reverse proxying, content hijacking, backlink injection, and selective redirection. BadIIS is described as a malicious native IIS module that loads into the IIS worker process and can inspect headers such as User-Agent and Accept-Language to cloak activity, inject SEO content for search-engine crawlers such as Googlebot, and serve clean content to administrators or regular users. Talos reported newer region-focused BadIIS variants including BadIIS IISHijack, primarily targeting Vietnam, and BadIIS asdSearchEngine, focused on Thailand or Thai-language users; some variants use XOR obfuscation with key 0x7A. Elastic Security Labs linked a campaign compromising more than 1,800 Windows servers globally to UAT-8099. Cisco Talos reported significant operational overlap between UAT-8099 and the WEBJACK campaign, citing shared malware hashes, command-and-control infrastructure, victimology, and promoted gambling sites. Some public reporting recommends treating UAT-8099 and WEBJACK as one practical cluster for hunting and incident response. Related activity is discussed alongside other IIS SEO-fraud clusters such as DragonRank, GhostRedirector, and Operation Rewrite, but the content does not establish them as the same actor. Known aliases and closely associated labels in the provided content include WEBJACK.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor observed attacking poorly managed Windows IIS and Apache Tomcat web servers in Windows environments. The activity involved uploading web shells, attempting privilege escalation, remote control, SEO manipulation, and broader server takeover, with evidence of LockBit 3.0 ransomware use.
Cybercrime group using BadIIS variants to compromise web servers for search engine manipulation and SEO fraud.
Large-scale SEO poisoning and IIS server compromise campaign using BADIIS malware; monetization via redirecting users to gambling ads/illicit sites; broad global victimology including government, corporate, and education.
Compromises IIS (Internet Information Services) Windows servers at scale and deploys the BADIIS malicious native IIS module to perform SEO poisoning via split-view content injection/redirects, monetizing access by promoting illicit gambling and fraudulent cryptocurrency sites while evading detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.