UAT-8099 Cyber Attack Targets IIS Servers in Asia with BadIIS Malware
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The UAT-8099 threat actor, linked to China, has been active since April 2025, focusing on vulnerable IIS servers across Asia. Cisco Talos discovered this campaign between late 2025 and early 2026, with a notable concentration of attacks in Thailand and Vietnam. The group exploits security vulnerabilities or weak configurations in IIS servers to gain access and deploy the BadIIS malware, which is used for SEO fraud.
UAT-8099 employs various tools and techniques, including web shells and PowerShell scripts, to maintain control over compromised servers. The malware variants, BadIIS IISHijack and BadIIS asdSearchEngine, are tailored to target users in Vietnam and Thailand, respectively. The attack chain involves creating hidden user accounts like ‘admin$’ and ‘mysql$’ to ensure ongoing access and evade detection.
Additionally, the threat actor has refined its methods by using GotoHTTP for remote control of infected servers. This tool is launched via a Visual Basic Script executed through PowerShell commands. The malware’s primary objective is to redirect search engine crawlers to fraudulent SEO sites while injecting malicious JavaScript into responses for regular users with Thai language preferences.
Understanding the BadIIS Variants
Three distinct variants of the BadIIS malware have been identified, each with specific functionalities:
- Exclusive multiple extensions variant, which ignores requests with certain file extensions to avoid resource-intensive processing.
- Load HTML templates variant, which dynamically generates web content by loading templates and replacing placeholders with random data.
- Dynamic page extension/directory index variant, which checks if a requested path corresponds to dynamic pages for effective injection.
These developments indicate a significant evolution in UAT-8099’s operational strategy, focusing on regional targets and employing sophisticated techniques to maintain stealth and persistence.
Key Takeaways
- Regularly update and patch IIS servers to protect against known vulnerabilities.
- Implement strong access controls and avoid using default or weak account names like ‘admin$’.
- Monitor server logs for unusual account activity or unauthorized access attempts.
- Utilize security tools to detect and block web shells and other malicious scripts.
- Educate staff about the risks of SEO fraud and the importance of cybersecurity hygiene.
Key Terms & Concepts
- BadIIS: In this article, BadIIS refers to malware used by the UAT-8099 threat actor to facilitate SEO fraud.
- UAT-8099: UAT-8099 is a China-linked cyber threat actor known for targeting IIS servers to deploy malware.
- IIS: IIS stands for Internet Information Services, a web server software created by Microsoft.
- SEO fraud: SEO fraud involves manipulating search engine results to drive traffic to malicious sites.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.