{"id":10291,"date":"2026-01-31T10:03:45","date_gmt":"2026-01-31T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/31\/uat-8099-targets-vulnerable-iis-servers-using-web-shells-powershell-and-region-customized-badiis\/"},"modified":"2026-01-31T10:03:45","modified_gmt":"2026-01-31T10:03:45","slug":"uat-8099-targets-vulnerable-iis-servers-using-web-shells-powershell-and-region-customized-badiis","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/31\/uat-8099-targets-vulnerable-iis-servers-using-web-shells-powershell-and-region-customized-badiis\/","title":{"rendered":"UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS"},"content":{"rendered":"<p>    UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. <\/p>\n<p>The campaign, active from late 2025 through early 2026, focuses primarily on victims in Thailand and Vietnam, marking a strategic shift toward region-specific operations. <\/p>\n<p>The attackers exploit unpatched IIS servers to inject malicious web shells, execute PowerShell scripts, and deploy the BadIIS malware, which now includes hardcoded regional configurations tailored to specific countries.<\/p>\n<p>The threat campaign demonstrates operational overlap with the previously documented WEBJACK operation, sharing common indicators such as malware signatures, command and control infrastructure, and targeted victim profiles. <\/p>\n<p>Attackers leverage web shells as their initial foothold, allowing them to execute commands remotely on compromised servers. <\/p>\n<p>Following successful infiltration, they deploy <a href=\"https:\/\/cybersecuritynews.com\/new-koiloader-abuses-powershell-scripts\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell scripts<\/a> to download and execute the GotoHTTP remote access tool, granting persistent control over infected systems. <\/p>\n<p>This multi-stage infection chain enables threat actors to maintain long-term access while avoiding detection through the use of legitimate administrative tools.<\/p>\n<p>Cisco Talos analysts <a href=\"https:\/\/blog.talosintelligence.com\/uat-8099-new-persistence-mechanisms-and-regional-focus\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the campaign after observing suspicious activity across multiple IIS deployments in South and Southeast Asia. <\/p>\n<p>The researchers noted that BadIIS variants now embed country codes directly into their source code, creating specialized versions for Vietnam (identified by \u201cVN\u201d tags) and Thailand (marked with \u201cTH\u201d designations). <\/p>\n<p>These customized variants include region-specific file extensions, dynamic page configurations, and localized HTML templates that facilitate search engine optimization fraud targeting specific language preferences.<\/p>\n<p>The malware\u2019s evolution reflects a more targeted approach compared to earlier versions. Each BadIIS variant filters web traffic based on the \u201cAccept-Language\u201d header to verify the visitor\u2019s region before delivering malicious payloads. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQ_s6ELteYdfmObpTcAy9tUbpRxPeaWgTSny3x8SD3m4nk1OhxSikjB9n2OrEHKPC747HqAT8VHfzPM0WgVt1_6WM_nbgD5c4-TbMXFV34tB9Unmv6e_5u1ayhSNNHpmJ_rUxa_Uhf1xIN9LZKxfmgYzuFr-nkLfky3Z6S4Bo9BrHqkWccKHEiQExNnr4\/s16000\/Content%2520for%2520crawlers%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"Content for crawlers (Source - Cisco Talos)\"><figcaption class=\"wp-element-caption\">Content for crawlers (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>When search engine crawlers visit infected sites, they are redirected to fraudulent gambling websites, while regular users receive injected JavaScript that silently redirects their browsers to malicious destinations.<\/p>\n<h2 class=\"wp-block-heading\" id=\"persistence-mechanisms-and-hidden-account-creation\"><strong>Persistence Mechanisms and Hidden Account Creation<\/strong><\/h2>\n<p>After establishing initial access, the threat actors create hidden user accounts to maintain persistent control over <a href=\"https:\/\/cybersecuritynews.com\/1500-postgresql-servers-compromised\/\" target=\"_blank\" rel=\"noreferrer noopener\">compromised servers<\/a>. <\/p>\n<p>The attackers initially used an account named \u201cadmin$\u201d but shifted to alternative names like \u201cmysql$,\u201d \u201cadmin1$,\u201d \u201cadmin2$,\u201d and \u201cpower$\u201d after security products began detecting the original naming pattern.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj4hbglsshxoOo4TXsvyvVZ5h9MeGNfVxAPAvMDHg5PqneNlKuh_g6ukSNF6qreKCGtnVq5-8sZpImV2Js-rrRoJqVQfLWIHLY8mUzAfU-jarVIzXKI0FZy5cQJd53FdOh3-ofG7WJnoD-9N39Jb0Ta017nEniGD5nm65wSQHgOry5lSgSybm9YBV8-AXc\/s16000\/BadIIS%2520IISHijack%2520version%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"BadIIS IISHijack version (Source - Cisco Talos) \"><figcaption class=\"wp-element-caption\">BadIIS IISHijack version (Source \u2013 Cisco Talos) <\/figcaption><\/figure>\n<\/div>\n<p>These accounts are assigned administrative privileges and used to deploy updated versions of BadIIS malware to specific regional directories such as \u201cC:\/Users\/mssql$\/Desktop\/VN\/\u201d for Vietnam-targeted operations and \u201cC:\/Users\/mssql$\/Desktop\/newth\/\u201d for Thailand-focused attacks. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEivmJSCGjkClp4gkpbrT8UAobcHTV_MzFfJuwNnb3g1DlnHDT58hKVJgWa5nKyf8sJAXn9NiBo12QFg59iMvo6vFVAGvjEOpsvb3DOszmrn73cH3vpeAQkKe2HE9oB-gVGpjxuHDhfKlXl8NwiDgYrqm1pub4rjRFXxi9DiIr8yjqG8zrl5ltRmfpbqoUM\/s16000\/Extensions%2520list%2520for%2520filtering%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"Extensions list for filtering (Source - Cisco Talos)\"><figcaption class=\"wp-element-caption\">Extensions list for filtering (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>The threat actors also deploy anti-forensic tools including Sharp4RemoveLog to erase <a href=\"https:\/\/cybersecuritynews.com\/windows-event-logs-reveal-the-messy-reality\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows event logs<\/a>, CnCrypt Protect to hide malicious files, and OpenArk64 to terminate security processes at the kernel level, ensuring their operations remain undetected for extended periods.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/uat-8099-targets-vulnerable-iis-servers\/\">UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/uat-8099-targets-vulnerable-iis-servers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active from late 2025 through early 2026, focuses primarily on victims in Thailand and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10291","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10291"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10291"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10291\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}