Back Scworld Vulnerable Asian IIS servers subjected to UAT-8099 targeting
Chinese-speaking cybercrime operation UAT-8099 has targeted unsecured Internet Information Services servers across Asia, particularly in Thailand and Vietnam, as part of an attack campaign that commenced late last year, reports Cyber Security News .
Initial access enabled by illicit web shell injections on vulnerable IIS servers has been leveraged by UAT-8099 to launch PowerShell scripts that run the GotoHTTP remote access tool for persistence and the eventual delivery of updated BadIIS malware variants, which have source code containing country codes for more targeted compromise, according to Cisco Talos analysts. Visiting websites impacted by the BadIIS malware results in redirections to fake gambling sites. UAT-8099 was also discovered to have leveraged the Sharp4RemoveLog, OpenArk64, and CnCrypt Protect tools for covert operations.
Meanwhile, malware signatures, command-and-control infrastructure, and victim profiles in the attack campaign also had similarities with the previously reported WEBJACK operation, said researchers.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
