A Chinese-speaking cybercrime group, tracked as UAT-8099, has been identified targeting high-value Microsoft Internet Information Services (IIS) servers across multiple countries, including India, Thailand, Vietnam, Canada, and Brazil. The group’s primary objective is to conduct search engine optimization (SEO) fraud by manipulating search rankings through the compromise of reputable IIS servers. UAT-8099 leverages a variety of tools and techniques, including the deployment of BadIIS malware, web shells, open-source hacking utilities, and Cobalt Strike to maintain persistence and evade detection on compromised systems. The attackers use customized automation scripts to further obfuscate their activities and ensure continued access. Once inside a target server, the group exploits vulnerabilities to upload web shells, which are then used to collect sensitive information such as credentials, configuration files, logs, and certificate data. This stolen data is likely packaged for resale or used in further criminal operations. Cisco Talos researchers discovered several new BadIIS malware samples associated with this campaign, noting that some clusters had very low detection rates and others contained debug strings in simplified Chinese, indicating the group’s origin. The campaign has affected a diverse set of organizations, including universities, technology companies, and telecommunications providers, highlighting the group’s broad targeting strategy. UAT-8099’s operations are financially motivated, with a focus on monetizing both the manipulation of search engine results and the theft of valuable credentials. The group also utilizes Remote Desktop Protocol (RDP) to access and further exploit compromised IIS servers. The technical sophistication of the campaign is evident in the attackers’ ability to evade traditional security measures and maintain long-term persistence. The use of reputable, high-value servers for SEO fraud increases the impact of the campaign, as these servers are more likely to influence search engine rankings. The campaign demonstrates the ongoing threat posed by financially motivated cybercrime groups leveraging advanced malware and exploitation techniques. Security researchers recommend organizations running IIS servers implement robust monitoring, patch management, and incident response procedures to detect and mitigate such threats. The exposure of configuration files and certificates also raises concerns about potential follow-on attacks, including lateral movement and further credential abuse. The campaign’s discovery underscores the importance of threat intelligence sharing and proactive defense measures in protecting critical web infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos released detection guidance tied to the campaign, including specific Snort SIDs and ClamAV signatures for the ASP.NET web shell, Cobalt Strike beacon, and BadIIS variants. This public disclosure provided defenders with technical indicators and detection coverage for the observed activity.
Cisco Talos disclosed that UAT-8099 used BadIIS variants for proxying, content injection, and crawler-targeted SEO manipulation, alongside Cobalt Strike, RDP persistence, and tunneling tools such as SoftEther VPN, EasyTier, and FRP. Talos also reported observing credential and sensitive-data theft, including LSASS dumping and certificate/configuration exfiltration, and identified new BadIIS samples uploaded to VirusTotal in 2025 that suggested ongoing malware development to evade detection.
A Chinese-speaking cybercrime group tracked as UAT-8099 compromised reputable IIS servers across countries including India, Thailand, Vietnam, Canada, and Brazil, affecting organizations such as universities, technology companies, and telecommunications providers. The group abused weak file-upload controls to deploy ASP.NET web shells, gain interactive access, and manipulate search results to redirect users to unauthorized ads and illegal gambling content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcedarkreading.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.