Malware
IISpy
Also known as: BadIIS
Indicators of Compromise 22
Domain adminapi[.]tippusoni[.]in Domain vn[.]xyz Filename C:\Windows\System32\drivers\etc\hosts:cache Filename XMRig Filename acpi_pad.ko Filename back.bat Filename back.txt Filename bai.bat Filename check_paths.py Filename demo.pdb Filename deploy_implant.py Filename deploy_shell.py Filename dll.zip Filename prcc1.rar Filename service.pdb Filename sss.ashx Filename svchosts.exe Filename up.ashx Filename user.bat GitHub Repo widestring-1.2.1 IP 139[.]180[.]197[.]150 Registry User index.crates.io-1949cf8c6b5b557f
MITRE ATT&CK TTPs 15
T1055 T1055.003 T1059.001 T1068 T1078 T1082 T1090 T1105 T1110 T1134 T1203 T1210 T1211 T1218 T1222
Process Injection
Defense Evasion
Thread Execution Hijacking
Defense Evasion
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Access Token Manipulation
Defense Evasion
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Exploitation for Defense Evasion
Defense Evasion
System Binary Proxy Execution
Defense Evasion
File and Directory Permissions Modification
Defense Evasion
Source Articles
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos identified a Chinese-speaking threat actor, UAT-10147, conducting a global campaign targeting Windows and Linux web servers in government, education, media, technology, and gaming sectors. The actor leverages publicly disclosed vulnerabilities for initial access, including CVE-2022-27925, CVE-2021-23758, and CVE-2019-18935, and uses AI-driven tooling to automate exploitation, reconnaissance, payload generation, and validation. Post-compromise, the actor deploys malware such as QuasarRAT, Gh0stCringe, and SPECTRE, establishes persistence via scheduled tasks and rogue user accounts, and uses AI-generated scripts to refine attacks and bypass defenses. A misconfigured command-and-control server at 139.180.197[.]150 exposed operational details, including a target list of 170,000 URLs and AI-assisted attack workflows.
talos ·3w ago
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
UAT-10147, a Chinese-speaking threat actor, is deploying a new cross-platform backdoor named SPECTRE that targets both Windows and Linux systems. The implant includes advanced capabilities such as process injection, credential theft, anti-analysis routines, and EDR evasion via Bring Your Own Vulnerable Driver (BYOVD) techniques. On Linux, SPECTRE deploys a kernel rootkit called Specter, disguised as 'acpi_pad.ko', which uses ftrace-based hooking to hide processes, modules, and enable UID 0 escalation. The actor also leverages SEO fraud tools like BadIIS and a custom ASHX web handler targeting Vietnamese users, along with multiple backdoors including Meterpreter, Noodle RAT, QuasarRAT, and Gh0stCringe for persistence.
talos ·3w ago
After the Break-In: What Attackers Do Once They're Already Inside
Huntress investigated a real-world incident in June 2026 where an attacker gained initial access via a SQL injection vulnerability on a web server. After entry, the attacker conducted reconnaissance, created a backdoor user, enabled Remote Desktop, disabled Windows Defender, and deployed multiple payloads including the BadIIS malware and the XMRig cryptocurrency miner. The attacker used PowerShell scripts to maintain persistence and evade detection, highlighting the importance of not only removing malware but also identifying and patching the initial vulnerability to prevent reinfection.
bleeping-computer ·1mo ago