Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS

Recent cyberattacks have been identified targeting Internet Information Services (IIS) servers in Asia, specifically exploiting vulnerabilities in systems across Thailand and Vietnam. This strategic operation, active from late 2025 through early 2026,…

Recent cyberattacks have been identified targeting Internet Information Services (IIS) servers in Asia, specifically exploiting vulnerabilities in systems across Thailand and Vietnam. This strategic operation, active from late 2025 through early 2026, involves the deployment of advanced malware designed to compromise these servers.

The attackers exploit unpatched IIS servers to inject malicious web shells, execute PowerShell scripts, and utilize the BadIIS malware, which now includes regional configurations tailored to specific countries. This campaign shares operational characteristics with the previously documented WEBJACK operation.

Initial access is gained through web shells, allowing remote command execution on compromised servers. Subsequently, PowerShell scripts are deployed to download and execute the GotoHTTP remote access tool, establishing persistent control over the systems.

Analysis by Cisco Talos indicates that BadIIS variants now embed country-specific codes, creating specialized versions for Vietnam and Thailand. These variants incorporate region-specific file extensions and HTML templates to facilitate targeted operations.

This strategic operation, active from late 2025 through early 2026, involves the deployment of advanced malware designed to compromise these servers.
Christine Neal · Thehackingpost

The malware filters web traffic based on the "Accept-Language" header to confirm the visitor's region before executing malicious payloads. Infected sites redirect search engine crawlers to fraudulent websites, while regular users receive injected JavaScript for redirection to malicious destinations.

Persistence Mechanisms and Hidden Account Creation

Upon gaining access, threat actors create hidden user accounts to maintain control over compromised servers. Initially, an account named "admin$" was used, but alternative names such as "mysql$", "admin1$", "admin2$", and "power$" have been adopted to avoid detection.

These accounts are granted administrative privileges and are used to deploy updated versions of BadIIS malware to specific regional directories, such as "C:/Users/mssql$/Desktop/VN/" for Vietnam-targeted operations and "C:/Users/mssql$/Desktop/newth/" for Thailand-focused attacks.

Advertisement

Anti-forensic tools, including Sharp4RemoveLog, CnCrypt Protect, and OpenArk64, are employed to erase Windows event logs, conceal malicious files, and terminate security processes, ensuring the threat actors' activities remain undetected for extended periods.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories