Elastic Security Labs reported a global SEO poisoning operation compromising Windows IIS web servers using a malicious IIS module dubbed BADIIS, attributed to a Chinese-speaking cybercrime group tracked as REF4033 and aligned with Cisco Talos’ UAT-8099. The activity observed in an intrusion at a multinational organization in Southeast Asia matches prior public reporting and is assessed to have impacted 1,800+ Windows servers across multiple sectors (including government, corporate, and education) in countries spanning Asia-Pacific, Europe, and Latin America. The operation uses a two-phase workflow: serving keyword-stuffed content to search engine crawlers to manipulate rankings, then redirecting real users to monetization destinations in the “vice economy,” including online gambling, pornography, and cryptocurrency schemes.
Additional research emphasized that multiple vendors are labeling overlapping slices of the same IIS SEO-fraud ecosystem differently, and recommended consolidating hunting for UAT-8099/WEBJACK-style activity based on shared indicators and behaviors. Defensive guidance focused on detecting new/unknown IIS module registrations and suspicious DLL/module naming and staging patterns (e.g., fashttp/fasthttp/cgihttp/iis32/iis64-style DLLs; staging under paths like Desktop\VN, Desktop\newth, Public\Videos), correlating anomalous local account creation patterns (e.g., $-suffixed accounts) and remote-access tooling on web servers, and using HTTP differential-response probing (varying User-Agent, Referer, Accept-Language) to identify cloaking behavior used to selectively serve crawler vs. user content.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-01, WithSecure Labs published research on the WEBJACK campaign, describing IIS server hijacking used to manipulate SEO and monetize traffic through fraudulent redirection. The report established WEBJACK as a tracked cluster of IIS abuse activity later compared with Talos' UAT-8099 and Elastic's BADIIS/REF4033 reporting.
On 2026-02-11, Elastic Security Labs published detailed analysis of the BADIIS malware and attributed the activity to a Chinese-speaking cybercrime group it tracks as REF4033, noting consistency with Cisco Talos' UAT-8099. The report revealed module-loading behavior, encrypted configuration methods, campaign infrastructure, and redirection logic used in the SEO-poisoning operation.
By early 2026, a large-scale campaign using the malicious IIS native module BADIIS had compromised over 1,800 Windows IIS servers worldwide, with a strong concentration in APAC, especially China and Vietnam. The operation manipulated search rankings and redirected users to gambling, pornography, and cryptocurrency fraud destinations.
On 2026-02-10, AlphaHunt argued that Talos' UAT-8099 and WithSecure's WEBJACK should be treated as a single practical hunting cluster based on overlaps in hashes, infrastructure, victimology, and outcomes. The post also outlined technical fingerprints for distinguishing this cluster from other BadIIS-style IIS SEO-fraud activity.
In November 2025, operators later linked to the BADIIS/REF4033 activity intruded into a multinational organization in Southeast Asia. Elastic reported the actor moved from initial access to IIS module deployment in under 17 minutes, using a webshell, creating an admin user, and installing a stealthy Windows service.
On 2024-05-09, AhnLab ASEC disclosed a campaign targeting poorly managed Windows IIS servers in South Korea that manipulated search results and redirected visitors to illegal online casino sites. The report detailed the attackers' use of a malicious IIS module alongside Meterpreter, HTran, a persistence account, and ProcDump-based LSASS dumping, and published hashes and infrastructure tied to the activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 77 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceelastic.co
Open sourceblog.alphahunt.io
Open sourcescworld.com
Open sourceasec.ahnlab.com
Open sourcelabs.withsecure.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.