UAT-8099 is a Chinese-speaking cybercrime threat cluster focused primarily on monetizing compromised Microsoft Internet Information Services (IIS) servers through search engine optimization fraud, traffic redirection, and theft of valuable data. The actor has been linked to campaigns that compromise reputable, high-value web servers and convert them into infrastructure for manipulating search rankings, redirecting users to gambling and other illicit content, and harvesting credentials, configuration files, and certificate material. Public reporting also notes substantial operational overlap with the WEBJACK campaign, and the two are often treated as a practical hunting cluster. UAT-8099 operates in the broader BadIIS ecosystem alongside adjacent but not definitively identical clusters such as DragonRank, GhostRedirector, and Operation Rewrite/CL-UNK-1037. The group commonly gains initial access through weak file-upload controls, vulnerable web applications, or exposed IIS services, then deploys web shells for command execution. Post-compromise activity includes reconnaissance, privilege escalation, enabling or creating privileged local accounts, activating remote desktop access, and establishing persistence through hidden accounts and scheduled tasks. UAT-8099 has repeatedly used remote-access and tunneling tools, including VPN and proxy utilities, to retain long-term control of compromised servers. Reporting also describes use of Cobalt Strike, DLL sideloading, PowerShell and script-based automation, anti-forensic tooling for log clearing, and utilities intended to disable or evade security controls. A defining feature of UAT-8099 activity is deployment of BadIIS malware and related malicious IIS components. These implants operate as native IIS modules or similar server-side traffic interception mechanisms that blend into normal web-server execution. They support reverse proxying, content hijacking, crawler-aware cloaking, JavaScript injection, backlink injection, and selective redirection based on request attributes such as referrer, user agent, or language. Campaigns have shown regional tailoring, especially for Thailand and Vietnam, including language-gated behavior and country-specific packaging. The actor has also used compromised servers to defend its foothold from competing intruders and to preserve exclusive access. Beyond SEO fraud, UAT-8099 has conducted credential theft and broader data exfiltration from victim servers, including collection of authentication material, configuration data, and certificates. Victim organizations publicly associated with the cluster include universities, technology companies, telecommunications providers, government entities, educational institutions, and financial organizations. Geographic targeting has been concentrated in Asia, especially Thailand and Vietnam, with additional victim infrastructure observed in India, Pakistan, Japan, Canada, Brazil, and elsewhere. In at least one reported 2026 case, activity believed to be associated with UAT-8099 escalated from web-shell access and server control to deployment of LockBit 3.0 ransomware, indicating the cluster or closely related operators can extend beyond SEO fraud into financially motivated extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor observed attacking poorly managed Windows IIS and Apache Tomcat web servers in Windows environments. The activity involved uploading web shells, attempting privilege escalation, remote control, SEO manipulation, and broader server takeover, with evidence of LockBit 3.0 ransomware use.
Cybercrime group using BadIIS variants to compromise web servers for search engine manipulation and SEO fraud.
Large-scale SEO poisoning and IIS server compromise campaign using BADIIS malware; monetization via redirecting users to gambling ads/illicit sites; broad global victimology including government, corporate, and education.
Compromises IIS (Internet Information Services) Windows servers at scale and deploys the BADIIS malicious native IIS module to perform SEO poisoning via split-view content injection/redirects, monetizing access by promoting illicit gambling and fraudulent cryptocurrency sites while evading detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.