Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-8099

Also known as: tracked as, Gopher Strike, Sheet Attack

Description

UAT‑8099 is a financially motivated threat actor that leverages widespread weaknesses in Microsoft IIS web servers to execute large‑scale fraud campaigns. Their primary method involves deploying custom variants of the BadIIS malware family, hardcoding geographic identifiers (e.g., VN, TH) into archive names and file extensions so that they can deliver region‑specific payloads. Using web shells injected through unrestricted file upload functions, the group runs PowerShell scripts that launch the GotoHTTP remote access tool, allowing attackers to exfiltrate configuration files, certificates, and credentials. Persistence is achieved through a combination of techniques: the creation of hidden Windows accounts (e.g., admin$, mysql$), exploitation of RDP and guest accounts, the use of VPN technologies like SoftEther and EasyTier, reverse proxies (FRP), scheduled tasks, and DLL sideloaded backdoors that may include Cobalt Strike beacons. The group also uses DLL sideloading tricks to masquerade backdoors as legitimate components, making detection harder. Tactics span credential dumping (T1003), data extraction (T1560), web‑shell exploitation and SEO poisoning (T1071, T1189), and credential theft, all supported by extensive reconnaissance of system state via discovery techniques. UAT‑8099’s operations are coordinated across multiple countries—including Vietnam, Thailand, China, and the United States—targeting diverse sectors such as finance, education, telecommunications, government, defense, IT, retail, manufacturing, gaming, healthcare, media, and energy.

Goals & Targeting

Targeted Sectors

Financial services
Education
Telecommunications
Government
Defense
Information technology
Retail
Manufacturing
Gaming
Healthcare
Media
Energy

Targeted Countries / Regions

VN
CN
IN
BR
JP
KR
PK
CA
US
AU
PL
GB

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 15 hours ago

Executive Summary

UAT‑8099 is a Chinese‐speaking cybercrime group that targets vulnerable IIS web servers worldwide, primarily through SEO poisoning and credential theft. They employ custom BadIIS variants hardcoded to regional codes, deploy GotoHTTP via PowerShell, create hidden user accounts for persistence, and leverage VPNs, FRP proxies, and DLL sideloaded backdoors for long‑term control.

Goals & Targeting

The group’s overarching goal is financial gain through large‑scale search engine manipulation and credential harvesting. By compromising any IIS server that meets minimal security prerequisites, UAT‑8099 can redirect web traffic to gambling or cryptocurrency portals tailored to the victim’s location, ensuring a higher conversion rate. Simultaneously, stealing credentials and configuration data allows attackers to expand footholds within enterprises. Their opportunistic approach—targeting publicly available, often unpatched servers across many countries—minimizes risk while maximizing reach, with no evidence of highly targeted or nation‑state level objectives.

Enhanced Description

Key Capabilities

  • Deploy web shells and PowerShell scripts on compromised IIS servers
  • Use GotoHTTP for remote access and configuration file exfiltration
  • Create hidden Windows user accounts (e.g., admin$, mysql$) for persistence and privilege escalation
  • Hardcode target regions into BadIIS malware variants using custom extensions and archive filenames
  • Perform SEO fraud and search‑engine poisoning campaigns targeting IIS servers
  • Upload web shells via unrestricted file upload vulnerabilities in IIS
  • Enable privileged RDP access through guest/admin accounts
  • Escalate privileges by manipulating or disabling default security settings
  • Maintain persistence with VPN tools (SoftEther, EasyTier) and reverse proxies (FRP)
  • Install scheduled tasks and DLL‑sideloaded backdoors for long‑term control
  • Steal credentials, configuration files, and certificate data from compromised systems

MITRE ATT&CK Tactics

Command and Control
Credential Access
Defense Evasion
Execution
Initial Access
Persistence
Privilege Escalation
Discovery
Resource Hijacking

ATT&CK Techniques

T1003
T1003.003
T1005
T1007
T1033
T1041
T1049
T1057
T1059.001
T1059.003
T1071.001
T1083
T1098
T1133
T1136.001
T1189
T1548
T1560
T1496
T1528
T1649

Software / Tooling

BadIIS
GotoHTTP
SoftEther VPN
EasyTier
FRP (Fast Reverse Proxy)
Cobalt Strike
ASP.NET Web Backdoor
Badiis

Campaigns & Victims

UAT‑8099 conducts global, geotargeted SEO poisoning campaigns that infiltrate hundreds of IIS servers across government agencies, enterprises, and the gaming industry. Their large scale—over 1,800 compromised hosts—demonstrates opportunistic exploitation rather than tailored spear‑phishing. The group customizes payloads per country to redirect traffic toward local gambling or cryptocurrency platforms, increasing fraud conversion rates while remaining covert through stealthy persistence mechanisms such as hidden accounts and VPN tunnels.

IOC Patterns

  • malware hash
  • C2 infrastructure indicator
  • hidden user account name (e.g., admin$, mysql$)
  • archive file name containing regional code (VN, TH)
  • custom file/directory naming patterns for region targeting
  • web‑shell upload via unrestricted file type in IIS
  • hardcoded domain for command and control servers
  • DLL sideloading of backdoor binaries
  • scheduled task creation for persistence
  • RDP usage enabled through guest/admin accounts
  • batch script automation for deployment
  • HTTP redirection URLs pointing to gambling or cryptocurrency sites
  • geolocation-based redirect patterns that match server country

Recommended Actions

  • Patch and harden IIS servers, especially in Southeast Asia, against known CVEs and upload vulnerabilities
  • Block or quarantine traffic associated with GotoHTTP tools and known BadIIS C2 domains
  • Monitor Windows event logs for creation of hidden user accounts ending in $ and unauthorized account changes
  • Implement web application firewalls to detect SEO poisoning scripts and block malicious JavaScript injections
  • Use file integrity monitoring on configuration files such as gotohttp.ini and other credential‑related files
  • Restrict file upload types and enforce strong authentication on IIS servers
  • Secure or disable guest RDP access and monitor for new scheduled tasks
  • Deploy endpoint protection that detects DLL sideloading, web-shell activity, and Cobalt Strike beacons
  • Enforce strict monitoring of VPN usage (SoftEther/EasyTier) to detect unauthorized persistence channels
  • Block traffic to known gambling or cryptocurrency domains used in redirect campaigns
  • Inspect IIS configuration for unauthorized redirects and reverse‑proxy settings

Suggested Tags

UAT-8099
GopherStrike
SheetAttack
BadIIS
GotoHTTP
WebShell
SEOPoisoning
Targeting-Vietnam
Targeting-Thailand
Vulnerable-IIS
SEO fraud
Credential theft
IIS exploitation
Chinese-speaking cybercrime group
RDP abuse
VPN persistence
Cobalt Strike
Geotargeted Redirects
Online Gambling Fraud
Cryptocurrency Scam
Large-scale Campaign
Government Targeting

Confidence Assessment

Confidence in the identified tactics, techniques, and operational patterns is moderate to high due to repeated observations across multiple reports and publicly available IOC data. However, gaps remain regarding the full extent of geographical coverage, specific victim impact metrics, and any potential evolution in tool usage beyond BadIIS and GotoHTTP. Continued monitoring of new IIS vulnerabilities and phishing vectors will be necessary to refine this intelligence.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. blog.talosintelligence.com — Cited by web research for: T1528
  2. blog.talosintelligence.com — Cited by web research for: GoToHTTP
  3. www.elastic.co — Cited by web research for: Unknown
  4. www.csoonline.com — Cited by web research for: Crisis
  5. thehackernews.com — Cited by web research for: WhatsApp

Intel Summary

21

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

Backdoor / C2
Malware
Fraud
Credential_Theft
Web_Attacks
IIS_Server
UAT-8099
GopherStrike
SheetAttack
BadIIS
GotoHTTP
WebShell
SEOPoisoning
Targeting-Vietnam
Targeting-Thailand
Vulnerable-IIS
SEO fraud
Credential theft
IIS exploitation
Chinese-speaking cybercrime group
RDP abuse
VPN persistence
Cobalt Strike
Geotargeted Redirects
Online Gambling Fraud
Cryptocurrency Scam
Large-scale Campaign
Government Targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.