WEBJACK is a cybercrime cluster associated with malicious Microsoft Internet Information Services (IIS) server compromises used for SEO fraud and traffic redirection, especially to gambling-themed scam content. Public reporting indicates WEBJACK substantially overlaps with Cisco Talos tracking under UAT-8099, with high-confidence correlations in malware, infrastructure, victimology, and redirect objectives; in practice, the two labels are best treated as the same operational cluster for hunting and incident response. The cluster targets exposed or vulnerable IIS web servers and uses web-shell-based initial access followed by PowerShell-driven deployment of remote-access tooling and malicious IIS components, including BadIIS-style native modules. Its core tradecraft centers on intercepting HTTP requests on compromised servers and selectively redirecting or injecting content for specific visitors. Observed cloaking includes serving different content to crawlers versus normal browsers, triggering redirects only when search-engine referrers are present, and gating behavior by language or geography, including Thai- and Vietnamese-oriented targeting logic. WEBJACK/UAT-8099 activity has been linked to persistence through remote-access tooling and local account manipulation on compromised web servers. Reported post-compromise behavior includes use of VPN and tunneling utilities, hidden or specially named local accounts, account re-enablement, and privilege changes to maintain access. Operations have also involved defense-evasion and operational-security tooling. The campaign has been described as Chinese-speaking and has primarily affected IIS servers across Asia, with particular emphasis on Thailand and Vietnam. Although WEBJACK operates in the broader BadIIS and IIS SEO-fraud ecosystem alongside clusters such as DragonRank, GhostRedirector, ESET Group 9/11, and Unit 42's CL-UNK-1037, those labels should not be treated as identical absent stronger corroboration. The dominant objective is monetization through fraudulent traffic redirection rather than espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Overlapping cluster with UAT-8099 focused on IIS SEO fraud and cloaking via malicious IIS modules (e.g., fashttp/fasthttp/cgihttp-named DLLs), enabling selective injection/redirects to gambling/scam destinations and supported by post-compromise remote access tooling.
Previously reported operation with similar malware signatures, C2 infrastructure, and victimology to the UAT-8099 campaign (suggesting possible linkage or shared tooling).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.