Executive Summary
In early 2024, the Chinese-language cybercrime group UAT-8099 orchestrated a sophisticated series of attacks targeting Internet Information Services (IIS) web servers belonging to reputable organizations worldwide, including technology firms, telecoms, and universities. Exploiting insecure internet-facing servers with weak file upload controls, the attackers established footholds using open source web shells. They escalated privileges, enabled remote access with OSS reverse proxy tools, and deployed 'BadIIS' implants to perform SEO poisoning, redirecting search engine traffic to fraudulent gambling and scam sites. Simultaneously, the threat actors exfiltrated credentials, configuration files, and certificates, setting the stage for future attacks or data sales on darknet markets.
This campaign demonstrates the threat actor's multi-pronged approach, blending fraud and espionage in ways that evade immediate detection. The incident highlights a growing global trend where SEO manipulation and credential theft converge, exposing organizations to operational, reputational, and regulatory risks amidst rising regulatory scrutiny around digital trust and supply chain integrity.
Why This Matters Now
The UAT-8099 campaign exploits common but still-prevalent web server misconfigurations, showing how attackers innovate to monetize compromised infrastructure for both fraud and deeper compromises. As search engine manipulation and data theft become increasingly entwined, organizations must swiftly patch external-facing assets and enhance visibility into lateral movement and anomalous traffic.
Attack Path Analysis
UAT-8099 gained access by exploiting an Internet-facing IIS server with unrestricted file uploads. They escalated privileges using a guest account to obtain administrator rights and enable RDP. Attackers moved laterally by deploying web shells and tools, securing exclusive access and potentially targeting other internal assets. Cobalt Strike and reverse proxies established command and control for persistent remote management. Sensitive data, credentials, and certificates were exfiltrated for future attacks or sale. The attack's impact was multifaceted: SEO poisoning, malicious redirects, and theft of organizational data—all performed with minimal visibility to victims.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a misconfigured IIS server allowing unrestricted file uploads to deploy a web shell and gain initial access.
Related CVEs
CVE-2021-31166
CVSS 9.8A remote code execution vulnerability exists in the HTTP protocol stack (http.sys) when it improperly handles objects in memory.
Affected Products:
Microsoft Windows 10 – 1909, 2004, 20H2
Microsoft Windows Server – 2004, 20H2
Exploit Status:
exploited in the wildCVE-2017-7269
CVSS 7.5A buffer overflow vulnerability in the WebDAV service in Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to execute arbitrary code via a crafted PROPFIND request.
Affected Products:
Microsoft Internet Information Services – 6.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Web Shell
Valid Accounts: Local Accounts
Create Account
Abuse Elevation Control Mechanism
Remote Access Software
Data Obfuscation
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Public-Facing Application Security
Control ID: 6.4.3
NIS2 Directive – Incident Handling & Reporting
Control ID: Article 21(2)d
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
CISA Zero Trust Maturity Model 2.0 – Least Privilege Enforcement
Control ID: Identity Pillar – Access Controls
DORA (Digital Operational Resilience Act) – ICT Security Controls
Control ID: Article 9(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Higher Education/Acadamia
Universities face critical exposure to IIS server compromises enabling SEO fraud, data theft, and reputation damage through BadIIS malware targeting educational infrastructure globally.
Telecommunications
Telecom providers vulnerable to UAT-8099 attacks on IIS servers, risking customer data exfiltration, network infrastructure compromise, and regulatory compliance violations across multiple regions.
Information Technology/IT
IT companies targeted for their reputable web presence, facing server hijacking, credential theft, and potential supply chain attacks through compromised infrastructure and client access.
Internet
Internet service organizations at high risk from web server malware infections, SEO poisoning attacks, and traffic redirection schemes that exploit trusted domain reputations.
Sources
- UAT-8099 Hijacks Reputable Sites for SEO Fraud & Thefthttps://www.darkreading.com/cyberattacks-data-breaches/uat-8099-hijacks-reputable-sites-seo-fraud-theftVerified
- UAT-8099: Chinese-speaking cybercrime group targets high-value IIS for SEO fraudhttps://blog.talosintelligence.com/uat-8099-chinese-speaking-cybercrime-group-seo-fraud/Verified
- Newly-discovered threat group hijacking IIS servers for SEO fraud, warns Cisco Taloshttps://www.csoonline.com/article/4067773/newly-discovered-threat-group-hijacking-iis-servers-for-seo-fraud-warns-cisco-talos.htmlVerified
- Cybercriminal Group UAT-8099 Exploits Compromised IIS Servers Worldwide for SEO Fraud and Data Thefthttps://www.thaicert.or.th/en/2025/10/08/cybercriminal-group-uat-8099-exploits-compromised-iis-servers-worldwide-for-seo-fraud-and-data-theft/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Enforcing Zero Trust segmentation, strong policy controls, and multi-cloud visibility would have constrained attacker movement, blocked unauthorized access, and detected anomalous actions across the attack lifecycle. Egress monitoring and encrypted traffic inspection could have further limited data theft and C2 communications.
Control: Zero Trust Segmentation
Mitigation: Unauthorized uploads to critical servers would be blocked or isolated.
Control: Multicloud Visibility & Control
Mitigation: Unusual privilege escalations would be detected.
Control: East-West Traffic Security
Mitigation: Lateral movement between hosts would be identified and blocked.
Control: Egress Security & Policy Enforcement
Mitigation: Suspicious outbound traffic to C2 domains would be denied.
Control: Encrypted Traffic (HPE)
Mitigation: Monitoring of encrypted flows would reveal anomalous exfiltration activity.
Hidden implants and malicious redirect behaviors would be surfaced and acted upon.
Impact at a Glance
Affected Business Functions
- Web Services
- IT Infrastructure
- Data Management
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive credentials, configuration files, and certificate data, leading to unauthorized access and data breaches.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation to limit direct access to public-facing workloads and critical assets.
- • Implement fine-grained egress controls to prevent unauthorized command & control or data exfiltration, even over encrypted channels.
- • Continuously monitor for privilege escalation and lateral movement using centralized multi-cloud visibility tools.
- • Deploy inline anomaly/threat detection at the workload and network layers for rapid identification of covert implants and malicious behaviors.
- • Regularly audit and harden server configurations, especially regarding upload permissions and exposed management interfaces.



