Also known as: tracked as, Gopher Strike, Sheet Attack
UAT‑8099 is a financially motivated threat actor that leverages widespread weaknesses in Microsoft IIS web servers to execute large‑scale fraud campaigns. Their primary method involves deploying custom variants of the BadIIS malware family, hardcoding geographic identifiers (e.g., VN, TH) into archive names and file extensions so that they can deliver region‑specific payloads. Using web shells injected through unrestricted file upload functions, the group runs PowerShell scripts that launch the GotoHTTP remote access tool, allowing attackers to exfiltrate configuration files, certificates, and credentials. Persistence is achieved through a combination of techniques: the creation of hidden Windows accounts (e.g., admin$, mysql$), exploitation of RDP and guest accounts, the use of VPN technologies like SoftEther and EasyTier, reverse proxies (FRP), scheduled tasks, and DLL sideloaded backdoors that may include Cobalt Strike beacons. The group also uses DLL sideloading tricks to masquerade backdoors as legitimate components, making detection harder. Tactics span credential dumping (T1003), data extraction (T1560), web‑shell exploitation and SEO poisoning (T1071, T1189), and credential theft, all supported by extensive reconnaissance of system state via discovery techniques. UAT‑8099’s operations are coordinated across multiple countries—including Vietnam, Thailand, China, and the United States—targeting diverse sectors such as finance, education, telecommunications, government, defense, IT, retail, manufacturing, gaming, healthcare, media, and energy.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT‑8099 is a Chinese‐speaking cybercrime group that targets vulnerable IIS web servers worldwide, primarily through SEO poisoning and credential theft. They employ custom BadIIS variants hardcoded to regional codes, deploy GotoHTTP via PowerShell, create hidden user accounts for persistence, and leverage VPNs, FRP proxies, and DLL sideloaded backdoors for long‑term control.
Goals & Targeting
The group’s overarching goal is financial gain through large‑scale search engine manipulation and credential harvesting. By compromising any IIS server that meets minimal security prerequisites, UAT‑8099 can redirect web traffic to gambling or cryptocurrency portals tailored to the victim’s location, ensuring a higher conversion rate. Simultaneously, stealing credentials and configuration data allows attackers to expand footholds within enterprises. Their opportunistic approach—targeting publicly available, often unpatched servers across many countries—minimizes risk while maximizing reach, with no evidence of highly targeted or nation‑state level objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAT‑8099 conducts global, geotargeted SEO poisoning campaigns that infiltrate hundreds of IIS servers across government agencies, enterprises, and the gaming industry. Their large scale—over 1,800 compromised hosts—demonstrates opportunistic exploitation rather than tailored spear‑phishing. The group customizes payloads per country to redirect traffic toward local gambling or cryptocurrency platforms, increasing fraud conversion rates while remaining covert through stealthy persistence mechanisms such as hidden accounts and VPN tunnels.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the identified tactics, techniques, and operational patterns is moderate to high due to repeated observations across multiple reports and publicly available IOC data. However, gaps remain regarding the full extent of geographical coverage, specific victim impact metrics, and any potential evolution in tool usage beyond BadIIS and GotoHTTP. Continued monitoring of new IIS vulnerabilities and phishing vectors will be necessary to refine this intelligence.
No campaigns linked yet.
No observed data linked yet.
21
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics