Cisco Talos reported a late-2025 to early-2026 campaign attributed to China-linked UAT-8099 targeting vulnerable Microsoft Internet Information Services (IIS) servers across Asia, with a notable concentration in Thailand and Vietnam. The actor uses web shells and PowerShell to run scripts and deploy the GotoHTTP remote-access tool, and has also been observed using SoftEther VPN and EasyTier to maintain control of compromised servers. The intrusions are used to deploy BadIIS, a malware family associated with black-hat SEO/SEO fraud activity.
Talos assessed the activity as having significant operational overlap with WithSecure’s WEBJACK campaign, citing correlations across malware hashes, C2 infrastructure, victimology, and even the gambling sites being promoted. Talos also described new BadIIS variants that hardcode the intended target region and include customized behaviors (e.g., specific file extensions and directory indexing configurations), and noted the existence of a Linux ELF BadIIS variant previously uploaded to VirusTotal that supports multiple modes (including proxy, injector, and SEO-fraud).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos published research describing the late-2025 to early-2026 UAT-8099 intrusion and SEO-fraud campaign against Asian IIS servers. The report detailed new persistence mechanisms, increased use of legitimate or red-team tools, and newly observed BadIIS variants customized by region.
Cisco Talos assessed that the UAT-8099 operation significantly overlapped with the previously documented WEBJACK campaign. The attribution was based on shared malware hashes, command-and-control infrastructure, victimology, and promoted gambling sites.
UAT-8099 deployed updated BadIIS malware on compromised IIS servers, including the Vietnam-focused IISHijack cluster and the Thailand-focused asdSearchEngine cluster. These variants filtered traffic by language or crawler behavior and redirected users or search engines to gambling and other SEO-fraud destinations.
After compromising IIS servers, the actor used web shells and PowerShell to conduct reconnaissance, create hidden local accounts such as "admin$" and "mysql$", and deploy the GotoHTTP remote access tool. The campaign also used utilities such as Sharp4RemoveLog, OpenArk64, and VPN or pivoting tools to evade detection and maintain long-term access.
A Linux ELF variant of BadIIS was uploaded to VirusTotal, indicating the malware family had expanded beyond Windows IIS environments. The sample supported proxy, injector, and SEO-fraud modes and used infrastructure consistent with later UAT-8099 reporting.
A campaign attributed to UAT-8099 began targeting vulnerable Microsoft IIS servers in Asia, with reporting indicating activity started by late 2024 and continued into 2025. Thailand and Vietnam emerged as key focus areas within the broader regional targeting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.