ASP.NET Web BackDoor is an open-source ASP.NET web shell used by the Chinese-speaking cybercrime group UAT-8099 in a Cisco Talos-reported campaign targeting high-value Microsoft Internet Information Services (IIS) servers. UAT-8099 gained initial access by abusing weak file-upload controls that did not restrict file types, then uploaded the web shell to the IIS webroot (Talos observed a deployment path of C:/inetpub/wwwroot/[REDACTED]/Html/hw/server.ashx). After deployment, the web shell was used to execute reconnaissance commands (e.g., ipconfig, whoami, arp, tasklist) and facilitate follow-on actions including enabling RDP for interactive access, enabling the Windows Guest account and elevating privileges, and creating a hidden persistence account (admin$) added to the local Administrators group. The broader intrusion activity associated with this web shell included use of tunneling/VPN tooling (SoftEther VPN, EasyTier, FRP) alongside RDP for persistent access, privilege escalation to SYSTEM, credential theft via LSASS dumping with ProcDump, collection of configuration files and certificate material (including inspection of .crt files via rundll32.exe cryptext.dll CryptExtOpenCER), staging data in Users\admin$\Desktop\loade\ and archiving with WinRAR for exfiltration. In this campaign, the web shell served as an initial foothold enabling deployment of additional payloads such as BadIIS variants (used for proxying/content injection and crawler-targeted SEO manipulation) and Cobalt Strike (executed via DLL sideloading with inetinfo.exe and scheduled-task persistence). Victim IIS servers were observed in India, Thailand, Vietnam, Canada, and Brazil, affecting organizations including universities, technology companies, and telecommunications providers; compromised servers were used to redirect end users (primarily mobile users on Android and iPhone) to unauthorized ads or illegal gambling content as part of SEO fraud operations. Talos detection guidance for related activity included Snort SIDs 65346 and 65345 and ClamAV detections including Win.Malware.NewBadIIS and Win.Packed.CSBeaconCn.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.