Chinese-speaking cybercrime group REF4033, also tracked as UAT-8099, compromised more than 1,800 Windows IIS servers worldwide to deploy the BADIIS malicious IIS module. Affected systems span government, corporate, education, healthcare, e-commerce, media, and financial organizations, with the largest concentration in China and Vietnam. The activity expands on previously reported BadIIS SEO-manipulation operations.
After gaining initial access through an undetermined method, the operators installed a webshell, created a local administrator account, and established a stealthy Windows service before inserting BADIIS into IIS request processing. The module selectively serves SEO backlinks to search-engine crawlers and redirects qualifying visitors to gambling, pornography, prostitution, and cryptocurrency-phishing sites. Region-specific infrastructure and filters for referrers, user agents, mobile devices, and server IP subnets help conceal the abuse while monetizing the reputation and search ranking of legitimate compromised domains.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs observed a REF4033 intrusion affecting a multinational organization based in Southeast Asia. The actors progressed from initial access to IIS-module deployment in under 17 minutes, using a webshell, an added local administrator account, and the WalletServiceInfo service to load BADIIS.
Chinese-speaking cybercrime group REF4033, also tracked as UAT-8099, compromised more than 1,800 Windows IIS servers globally and deployed the BADIIS malicious IIS module. The operation monetized legitimate sites by injecting search-engine backlinks and redirecting selected visitors to gambling, adult, prostitution, and cryptocurrency-fraud sites.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 65 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcetrendmicro.com
Open sourceired.team
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.