REF4033 is a Chinese-speaking cybercrime group associated with a large-scale SEO poisoning operation targeting Microsoft IIS web servers. The group has compromised more than 1,800 Windows web servers globally and uses a malicious IIS native module known as BADIIS to manipulate search-engine indexing and redirect users to illicit destinations. Reported monetization includes online gambling, pornography, and cryptocurrency fraud, including phishing themed around cryptocurrency services. The operation uses a two-stage workflow. First, compromised servers deliver keyword-stuffed or backlink-oriented content to search-engine crawlers to improve ranking and indexing. Second, normal visitors are selectively redirected to monetized destinations. The malware distinguishes bots from human users through User-Agent and Referer inspection and supports conditional behavior such as mobile-only targeting and subnet-based filtering. The actor also uses analytics tags to measure redirection performance. Observed post-compromise tradecraft includes rapid progression from initial access to IIS module deployment, use of a webshell under the IIS worker process, creation of a local administrator account, and installation of a stealth-oriented Windows service that loads an unsigned DLL under svchost. The service modifies its security descriptor to hinder tampering. The DLL stages BADIIS components, alters IIS configuration for the default application pool, and inserts attacker-controlled modules into the request pipeline. Samples have shown code protection and encrypted configuration retrieval, with newer variants using SM4 and older variants using AES. Victimology indicates broad targeting across government, corporate, and educational organizations, with a strong concentration in the Asia-Pacific region. Public-sector systems are among the affected environments. Related activity has been linked by researchers to tracking under the designation UAT-8099. REF4033 is best characterized as a financially motivated cybercrime actor specializing in server-side compromise, stealthy persistence on IIS infrastructure, SEO manipulation, and traffic redirection for vice-economy and cryptocurrency-fraud monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.