A Chinese-speaking threat actor, tracked as CL-UNK-1037, is conducting a sophisticated SEO poisoning campaign using custom IIS malware called BadIIS. The campaign targets East and Southeast Asia, compromising legitimate web servers to manipulate search results and redirect users to scam or illicit sites. The attackers employ multiple malware variants and share infrastructure with known groups such as Group 9 and DragonRank.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Unit 42 publicly reported that Operation Rewrite was operated with high confidence by a Chinese-speaking threat actor based on linguistic artifacts and infrastructure patterns. The report also linked CL-UNK-1037 to ESET's Group 9 with moderate confidence and noted low-confidence similarities to DragonRank.
As the investigation expanded, analysts discovered additional samples and infrastructure tied to the campaign, including 008php.com-family C2 domains. They also identified undocumented variants beyond native IIS modules, including an ASP.NET page handler, a managed .NET IIS module, and an all-in-one PHP script for cloaking, proxying, and sitemap rewriting.
During the campaign, the operators moved laterally to production servers and domain controllers, deployed additional web shells, created scheduled tasks and local users, and staged ZIP archives of web application source code in web-accessible paths for exfiltration. The activity showed a geographic focus on East and Southeast Asia, especially Vietnam.
In March 2025, researchers uncovered a wide-scale SEO poisoning campaign dubbed Operation Rewrite and tracked it as CL-UNK-1037. The activity involved compromised legitimate servers running BadIIS to manipulate search engine results and redirect users to scam content.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.