UAT-8099 is a Chinese-speaking cybercrime group known for SEO fraud and credential theft on IIS servers.
Analyst brief
UAT-8099 is a Chinese-speaking cybercrime group focused on SEO fraud and stealing high-value credentials, configuration files, and certificates from vulnerable IIS servers. They leverage web shells and PowerShell to deploy the GotoHTTP tool for remote access, while maintaining persistence through DLL sideloading, RDP, and the creation of hidden accounts with VPN tools. Defenders should monitor for unusual web shells, anomalous PowerShell activity, hidden user accounts, and IIS modifications indicative of SEO manipulation such as BadIIS variants.
UAT-8099
unknown
UAT-8099 is a Chinese-speaking cybercrime group primarily engaged in SEO fraud and the theft of high-value credentials, configuration files, and certificate data from vulnerable IIS servers. They utilize web shells and PowerShell to deploy the GotoHTTP tool for remote access, while also employing techniques such as DLL sideloading and RDP for persistence. The group has been observed using BadIIS variants for SEO manipulation and executing reconnaissance commands to gather system information. Additionally, they create hidden accounts and utilize VPN tools to maintain long-term access to compromised systems.