UAT-10147 is a Chinese-speaking cybercrime group that targets internet-exposed Windows and Linux web servers using publicly disclosed vulnerabilities for initial access. The group integrates AI-driven offensive tools including PentestGPT and DeepAudit to automate exploitation, reconnaissance, payload generation, and validation workflows. Post-compromise activities include deploying BadIIS for SEO fraud, QuasarRAT and SPECTRE implants for persistent access, and creating rogue local admin accounts on Windows systems. The actor demonstrated semi-autonomous offensive orchestration through AI-generated operational playbooks documenting complete ASP.NET ViewState deserialization RCE chains.
BadIIS
3 posts
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Home Field Advantage: How Attackers Reshape Victim Environments A threat actor exploited an SQL injection vulnerability in an IIS web application to gain initial access to a Windows endpoint running MSSQL. After access, the attacker performed extensive environment modifications including reconnaissance via tasklist, exfiltration to an OAST domain, creation of a new local administrator account, enabling Terminal Services, disabling Windows Defender, installing BadIIS modules, deploying an XMRig cryptocurrency miner with persistence, and adding CnCrypt Protect for defense evasion. The breadth of modifications on a single endpoint was notable compared to similar incidents.
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat Cisco Talos has identified a commodity BadIIS malware ecosystem operating under a Malware-as-a-Service (MaaS) model, primarily used by Chinese-speaking threat actors for SEO fraud and traffic manipulation. The developer, known as 'lwxat', provides a dedicated builder and sophisticated service-based installers that ensure persistence on compromised Windows IIS servers while evading detection through custom Base64 encoding and service impersonation.