UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS
Recent cyberattacks have been identified targeting Internet Information Services (IIS) servers in Asia, specifically exploiting vulnerabilities in systems across Thailand and Vietnam. This strategic operation, active from late 2025 through early 2026,…
Recent cyberattacks have been identified targeting Internet Information Services (IIS) servers in Asia, specifically exploiting vulnerabilities in systems across Thailand and Vietnam. This strategic operation, active from late 2025 through early 2026, involves the deployment of advanced malware designed to compromise these servers.
The attackers exploit unpatched IIS servers to inject malicious web shells, execute PowerShell scripts, and utilize the BadIIS malware, which now includes regional configurations tailored to specific countries. This campaign shares operational characteristics with the previously documented WEBJACK operation.
Initial access is gained through web shells, allowing remote command execution on compromised servers. Subsequently, PowerShell scripts are deployed to download and execute the GotoHTTP remote access tool, establishing persistent control over the systems.
Analysis by Cisco Talos indicates that BadIIS variants now embed country-specific codes, creating specialized versions for Vietnam and Thailand. These variants incorporate region-specific file extensions and HTML templates to facilitate targeted operations.
This strategic operation, active from late 2025 through early 2026, involves the deployment of advanced malware designed to compromise these servers.
The malware filters web traffic based on the "Accept-Language" header to confirm the visitor's region before executing malicious payloads. Infected sites redirect search engine crawlers to fraudulent websites, while regular users receive injected JavaScript for redirection to malicious destinations.
Persistence Mechanisms and Hidden Account Creation
Upon gaining access, threat actors create hidden user accounts to maintain control over compromised servers. Initially, an account named "admin$" was used, but alternative names such as "mysql$", "admin1$", "admin2$", and "power$" have been adopted to avoid detection.
These accounts are granted administrative privileges and are used to deploy updated versions of BadIIS malware to specific regional directories, such as "C:/Users/mssql$/Desktop/VN/" for Vietnam-targeted operations and "C:/Users/mssql$/Desktop/newth/" for Thailand-focused attacks.
Anti-forensic tools, including Sharp4RemoveLog, CnCrypt Protect, and OpenArk64, are employed to erase Windows event logs, conceal malicious files, and terminate security processes, ensuring the threat actors' activities remain undetected for extended periods.
Based on reporting by Cyber Security News.
