Chinese-Speaking Groups Exploit BadIIS for SEO Manipulation in Asia
Article Content
- •BadIIS malware is actively exploited by Chinese-speaking groups for SEO manipulation.
- •Compromised IIS servers can redirect users to malicious sites, impacting various sectors.
- •The malware has been under development since at least September 2021 and remains actively maintained.
Since 2024, multiple Chinese-speaking cybercrime groups have been exploiting a variant of BadIIS malware to manipulate SEO and inject malicious content into compromised Internet Information Services (IIS) servers across Asia. This malware targets vulnerable IIS servers, allowing attackers to alter HTTP responses and redirect users to unauthorized sites, including illegal gambling pages. Regions affected include India, Thailand, Vietnam, and South Korea, with attacks impacting government, educational, and telecommunications sectors. The malware's development has been traced back to at least September 2021, with ongoing updates noted as recently as January 2026. Both Talos and Trend Micro have reported on the malware's capabilities, highlighting its use in SEO fraud and content injection. The threat remains active, with significant implications for organizations relying on IIS servers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track BadIIS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to enhance its attack methods, transitioning from simple scripting to semi-autonomous offensive operations.…
UAT-10147 Threat Actor Deploys SPECTRE Backdoor with AI and EDR Bypass Techniques UAT-10147, a Chinese-speaking threat actor, has been identified using the SPECTRE backdoor and a Linux rootkit to conduct sophisticated multi-platform attacks. The group employs advanced techniques such as Bring Your Own Vulnerable Driver (BYOVD) to disable endpoint detection and response (EDR) protections. Cisco…