OpenArk64 is a tool used by the Chinese-speaking cybercrime cluster UAT-8099 during intrusions targeting unpatched or unsecured Microsoft IIS servers across Asia, particularly in Thailand and Vietnam. In the reported campaigns, attackers gained initial access by injecting web shells into vulnerable IIS servers, executed PowerShell, deployed GotoHTTP for persistence, and delivered BadIIS variants used for SEO fraud and redirection to gambling-related destinations. OpenArk64 was used as a defense-evasion utility to terminate security processes at the kernel level, helping the operators remain undetected for longer periods. The activity was assessed to overlap with the previously reported WEBJACK operation based on shared malware signatures, command-and-control infrastructure, and victimology. OpenArk64 was observed alongside other operational-security tools including Sharp4RemoveLog, used to erase Windows event logs, and CnCrypt Protect, used to hide malicious files. The content does not provide standalone infection vectors or indicators specific to OpenArk64 itself beyond its use in these IIS-focused intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-exploitation utility used to support covert operations on compromised hosts (specific functions not detailed in the content).
Post-compromise tool used for defense evasion by killing security/EDR processes using kernel-level capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.