WEBJACK is a cluster associated with malicious Microsoft IIS compromise and SEO-fraud/traffic redirection activity, assessed in the provided content as highly overlapping with Cisco Talos’ UAT-8099 and recommended to be treated as a single practical cluster for hunting/IR due to shared malware hashes, C2 infrastructure, victimology, and gambling-redirect outcomes. The activity targets unsecured/vulnerable IIS servers across Asia, with particular impact in Thailand and Vietnam, and has been reported active since late 2024. Tradecraft described includes initial access via illicit web shell injection on IIS servers, followed by PowerShell execution and deployment of remote-access tooling (notably GotoHTTP for persistence; also SoftEther VPN, EasyTier, and FRP are mentioned as post-compromise access methods). On-host process chains noted include web shell → PowerShell → wscript/cscript and subsequent remote-access tool execution. Persistence mechanisms include creation of local accounts with names ending in “$” (e.g., admin$, mysql$, admin1$, admin2$, power$), re-enabling disabled accounts such as Guest, and modifying group memberships into Admins or Remote Desktop Users. The core payload behavior is described as BadIIS-style malicious IIS components—often native IIS modules—used to intercept HTTP traffic and selectively inject or redirect users to gambling/scam content, with cloaking such as serving different content to crawlers vs browsers, redirecting only when a search-engine referrer is present, and locale gating (e.g., Accept-Language set to Thai or Vietnamese). Module filename/naming pivots associated with this activity include fashttp.dll, fasthttp.dll, cgihttp.dll, and iis32/iis64 naming conventions; staging/deployment paths mentioned include C:\Users*\Desktop\VN, C:\Users*\Desktop\newth, and C:\Users\Public\Videos. The content also notes that operators may rotate implementations (e.g., to ASP.NET handlers/managed modules/PHP controllers) while maintaining the same SEO-fraud objective. Additional tooling referenced in relation to UAT-8099/WEBJACK-style operations includes Sharp4RemoveLog, OpenArk64, and CnCrypt Protect. The content explicitly distinguishes adjacent reporting/labels (e.g., Unit 42 CL-UNK-1037/Operation Rewrite, ESET Group 9/11 buckets, Talos DragonRank, ESET GhostRedirector) as similar ecosystem activity but not proven identical to WEBJACK/UAT-8099 absent shared infrastructure/hashes; it also notes Unit 42’s assessment that CL-UNK-1037 is a high-confidence Chinese-speaking operator, while the UAT-8099 cluster is described as a Chinese-speaking cybercrime operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Overlapping cluster with UAT-8099 focused on IIS SEO fraud and cloaking via malicious IIS modules (e.g., fashttp/fasthttp/cgihttp-named DLLs), enabling selective injection/redirects to gambling/scam destinations and supported by post-compromise remote access tooling.
Previously reported operation with similar malware signatures, C2 infrastructure, and victimology to the UAT-8099 campaign (suggesting possible linkage or shared tooling).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.