CL-UNK-1037, also referred to as Operation Rewrite, is a threat cluster associated with malicious manipulation of Microsoft IIS web servers for SEO poisoning and traffic-redirect fraud. The activity sits within the broader BadIIS-style ecosystem and is linked to campaigns that intercept inbound HTTP requests and selectively rewrite, inject, or redirect traffic to scam or gambling-related destinations. Public reporting describes the cluster as a high-confidence Chinese-speaking operator. The actor’s tradecraft centers on compromising IIS-hosted websites and deploying server-side components that alter web responses based on request characteristics. Reported implementations include native IIS modules, ASP.NET handlers, managed .NET IIS modules, and PHP front-controller rewrite logic. This enables cloaking behavior in which search-engine crawlers, users arriving from search referrers, or visitors with particular language settings receive different content than ordinary browsers. Accept-Language-based gating, including Thai- and Vietnamese-oriented targeting logic, has been observed as part of this selective redirection behavior. CL-UNK-1037 is associated with post-compromise web-server manipulation rather than ransomware or destructive operations. Its capabilities include initial access to exposed web infrastructure, persistence on compromised servers, defense evasion through cloaked conditional content delivery, and post-exploitation focused on maintaining and monetizing illicit traffic flows. The cluster has been discussed alongside other IIS SEO-fraud groupings such as ESET Group 9 and DragonRank. A moderate-confidence relationship to ESET Group 9 has been reported based on design similarities and overlapping command-and-control domain-family patterns, while a connection to DragonRank has been assessed only at low confidence due to similar tradecraft without confirmed infrastructure overlap. These adjacent labels should be treated as related ecosystem clusters rather than proven synonyms.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Likely Chinese-speaking cluster conducting SEO poisoning (Operation Rewrite) to redirect traffic and plant web shells (BadIIS).
Adjacent IIS SEO-poisoning cluster that can implement the same objective via multiple web-stack mechanisms (native IIS modules, ASP.NET handlers, managed .NET IIS modules, and PHP front-controller 'rewrite' model); discussed as ecosystem-adjacent to UAT-8099/WEBJACK rather than a proven alias.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.