UAT-8099
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
UAT-8099 is a Chinese-speaking cybercrime group that emerged in April 2025, primarily motivated by financial gain through search engine optimization (SEO) fraud and the theft of high-value credentials, configuration files, and certificate data. The group distinguishes itself by actively targeting reputable Internet Information Services (IIS) servers to manipulate search rankings, leveraging the trusted nature of these servers for their illicit activities. They have demonstrated an evolution in their tactics, shifting towards regionally targeted campaigns with customized BadIIS malware variants and incorporating advanced persistence techniques, including a Linux version of their primary malware.