216.73.217.80

Dissecting UAT-8099: New persistence mechanisms and regional focus

· Published 29/01/2026 17:20 · Modified 30/01/2026 08:19

Export JSON

Essential information

Published
29/01/2026 17:20
Modified
30/01/2026 08:19
Tags
2026-01-29 asia badiis gotohttp iis persistence powershell regional targeting seo fraud thailand vietnam web shells
Related entities
74 observables, 1 intrusion sets (apt), 2 malware, 23 others

Description

UAT-8099, a threat actor targeting vulnerable servers across , has launched a new campaign from late 2025 to early 2026. The group's tactics have evolved, focusing on and , and employing , scripts, and the tool for remote access. New variants of malware now include region-specific features, with separate versions targeting and . The actor has expanded their toolkit to include utilities for log removal, file protection, and anti-rootkit capabilities. They've also adapted their methods, creating hidden user accounts and leveraging legitimate tools to evade detection. The campaign demonstrates significant operational overlaps with the WEBJACK campaign, including shared malware hashes, C2 infrastructure, and victimology.

External references