UAT-8099UAT-8099

Also known as: UAT-8099

Known aliases
1

Profile

UAT-8099 is a Chinese-speaking cybercrime group primarily engaged in SEO fraud and the theft of high-value credentials, configuration files, and certificate data from vulnerable IIS servers. They utilize web shells and PowerShell to deploy the GotoHTTP tool for remote access, while also employing techniques such as DLL sideloading and RDP for persistence. The group has been observed using BadIIS variants for SEO manipulation and executing reconnaissance commands to gather system information. Additionally, they create hidden accounts and utilize VPN tools to maintain long-term access to compromised systems.

Aliases· 1

UAT-8099

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UAT-5918
Actor
UTG-Q-008
Actor
UAT-8302
Actor
UTA0388
Actor
UAT-6382
Actor
UAC-0099
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.