BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Cybercriminals Exploit IIS Servers for SEO Fraud, Data Theft

Chinese-speaking cybercrime group UAT-8099 exploits Microsoft IIS servers for SEO fraud and data theft across multiple countries using customized malware and advanced hacking tools.

  • A Chinese-speaking cybercriminal group named UAT-8099 targets Microsoft Internet Information Services (IIS) servers to commit SEO fraud and steal sensitive data.
  • The group operates mainly in India, Thailand, Vietnam, Canada, and Brazil, targeting universities, tech companies, and telecom providers.
  • They exploit security weaknesses to install web shells, escalate privileges, enable Remote Desktop Protocol (RDP), and deploy customized Malware like BadIIS.
  • UAT-8099 uses various tools including open-source software, Cobalt Strike, and VPN services to maintain persistence and evade detection.
  • The group’s malware alters web traffic to boost search engine rankings through backlink manipulation, redirecting users to unauthorized ads or gambling sites.

Cybersecurity researchers have identified a Chinese-speaking cybercrime group called UAT-8099 responsible for search engine optimization (SEO) fraud and the theft of high-value credentials, configuration files, and certificates. The group primarily targets Microsoft Internet Information Services (IIS) servers and was first observed in April 2025. Most attacks have been reported across India, Thailand, Vietnam, Canada, and Brazil, focusing on mobile users with Android and Apple devices.

- Advertisement -

According to Cisco Talos researcher Joey Chen, UAT-8099 attacks reputable IIS servers in targeted regions to manipulate search rankings. The group employs web shells, open-source Hacking tools, Cobalt Strike, and customized BadIIS malware to maintain access and conceal their activities. They exploit vulnerabilities or weak server file upload settings to gain initial entry.

After breaching a server, UAT-8099 escalates user privileges by enabling the guest account and activating Remote Desktop Protocol (RDP) access. The group secures their control by blocking other attackers’ access and uses RDP combined with VPN tools like SoftEther VPN, EasyTier, and Fast Reverse Proxy (FRP) to sustain persistence.

UAT-8099 then installs a variant of BadIIS malware, similar to previously known threats such as Gamshen, which activates only when requests come from Google by checking if the user agent is Googlebot. This malware operates in three modes: proxying to communicate with command-and-control (C2) servers, injecting malicious JavaScript into responses to redirect users to unauthorized ads or gambling sites, and conducting SEO fraud through backlinking.

The group uses a graphical search tool called Everything within the compromised IIS servers to locate valuable information, which they then package for resale or further exploitation. Yet, the total number of compromised servers remains unknown.

- Advertisement -

Cisco Talos explained that backlinking—a technique involving links pointing to a website—is commonly used to increase search engine visibility. However, accumulating backlinks indiscriminately can result in penalties from Google, making the group’s approach risky despite its potential for financial gain.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ex-FTX engineer Nishad Singh fined $3.7 million

Former FTX head of engineering Nishad Singh settled a Commodity Futures Trading Commission (CFTC)...

Tether’s Jesse Spiro to Chair $100M Crypto Super PAC

Tether's Head of Government Affairs, Jesse Spiro, will chair the crypto-funded Fellowship PAC ahead...

CERT-UA Impersonated, New RAT Attack Hits Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) was impersonated in a phishing campaign...

Binance Launches Oil and Gas Futures with 100x Leverage

Binance has officially launched trading for oil and natural gas futures contracts, completing its...

Franklin Templeton Buys 250 Digital to Launch Crypto Unit

Franklin Templeton is establishing a dedicated crypto unit, Franklin Crypto, through the acquisition of...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading