UAT-8099

First seen
2021-05-01 00:00:00
Origin
CN
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Last IoC activity
2026-06-22 02:34:54
Profile updated
2026-07-07 12:23:52

Targeted industries: financial-services technology-and-telecommunications media-and-entertainment

Context

UAT-8099 is a Chinese-speaking cybercrime group primarily engaged in SEO fraud and the theft of high-value credentials, configuration files, and certificate data from vulnerable IIS servers. They utilize web shells and PowerShell to deploy the GotoHTTP tool for remote access, while also employing techniques such as DLL sideloading and RDP for persistence. The group has been observed using BadIIS variants for SEO manipulation and executing reconnaissance commands to gather system information. Additionally, they create hidden accounts and utilize VPN tools to maintain long-term access to compromised systems.

Reports & references

  • Cisco Talos — Uat 8099 New Persistence Mechanisms And Regional Focus (report)
  • Cisco Talos — Uat 8099 Chinese Speaking Cybercrime Group Seo Fraud (report)

External references