CnCrypt Protect is a tool used by the Chinese-speaking cybercrime cluster UAT-8099 during intrusions against unpatched or unsecured Microsoft IIS servers in Asia, particularly in Thailand and Vietnam. In the reported campaigns, attackers gained initial access by injecting web shells into vulnerable IIS servers, executed PowerShell, deployed GotoHTTP for persistence, and delivered BadIIS variants used for SEO fraud and redirection to fake gambling sites. Within this intrusion set, CnCrypt Protect was specifically used as an anti-forensic or evasion utility to hide malicious files on compromised systems. The activity has been linked by researchers to operational overlap with the previously reported WEBJACK operation based on shared malware signatures, command-and-control infrastructure, and victimology. High-confidence associated tooling in the same campaigns includes Sharp4RemoveLog, OpenArk64, GotoHTTP, and BadIIS. Targeting focused on IIS infrastructure across South and Southeast Asia, with emphasis on Thailand and Vietnam.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used to protect/obfuscate payloads or tooling for covert operations (exact behavior not detailed in the content).
Tool used to conceal/protect malicious files on disk (likely via encryption/packing/obfuscation) to reduce detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.