HomeCyber BalkansUAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data...

UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft

Published on

spot_img

UAT-10147: A Cybercrime Group Targeting Global Web Servers

A recent investigation has highlighted the activities of a sophisticated cybercrime group identified as UAT-10147, primarily targeting vulnerable Windows and Linux web servers across the globe. This Chinese-speaking group is known for deploying the BadIIS malware, which is designed to steal data and manipulate search engine results to generate financial profits. Their approach employs both established hacker techniques and advanced technological aids, marking a significant evolution in cybercrime operations.

Global Reach and Victim Profile

Talos, a renowned cybersecurity research team, reported that the victims of UAT-10147 are diverse, spanning several nations including Brazil, Bolivia, China, Canada, and Vietnam. The affected organizations are varied, encompassing government bodies, educational institutions, media outlets, technology firms, and gaming companies. This wide-ranging impact underscores the group’s extensive reach and the significance of their malicious operations.

In an intriguing turn of events, a lapse in the group’s operational security revealed an attacker download server, located at the IP address 139.180.197[.]150. This compromise led researchers to discover an open directory containing an alarming target list of approximately 170,000 URLs. The fact that this list was organized into 17 separate files, each containing around 10,000 URLs, demonstrates a methodical and high-volume strategy for identifying and exploiting internet-facing infrastructures.

Exploitation Techniques

Initial access for UAT-10147 primarily hinges upon the exploitation of publicly disclosed remote code execution (RCE) vulnerabilities. The group has notably demonstrated proficiency in utilizing weaknesses such as Zimbra CVE-2022-27925, AjaxPro CVE-2021-23758, Nacos CVE-2021-29441 and CVE-2021-29442, as well as Telerik UI for ASP.NET AJAX CVE-2019-18935. The exploitation of Nacos, in particular, is noteworthy. By collecting basic host telemetry and sending it to an Nacos configuration service controlled by the attackers, the group not only confirms successful compromises but does so without maintaining a regularly monitored interactive shell.

Cisco Talos has characterized this operation as a significant evolution in the realm of criminal web-server activity. The group combines publicly known vulnerabilities with AI-assisted exploit development, reconnaissance, and persistence strategies.

Methods of Compromise

For Windows IIS servers, UAT-10147 typically implements staged batch scripts following a successful remote code execution attack. These scripts utilize the certutil tool to retrieve malicious payloads. Notable tools involved include EfsPotato for privilege escalation, and QuasarRAT, which is often disguised as svchosts.exe. Following this, the operators elevate their privileges and modify Microsoft Defender’s exclusion paths via PowerShell and Registry changes. This creates a covert zone around the IIS directories, allowing them to deploy BadIIS modules undetected.

The group effectively enumerates IIS sites using the appcmd utility. This procedure helps in pinpointing valuable injection points, while they ensure long-term access by creating rogue local users that possess Administrator and Remote Desktop Users group memberships. Talos has also observed the establishment of scheduled tasks that masquerade as innocuous items like "Google Chrome Start," which are configured to launch the malware with elevated privileges during user logon.

Targeting Linux Systems

On Linux systems, UAT-10147 deploys web shells following the exploitation of vulnerable applications. They then execute local privilege escalation using a wide array of known vulnerabilities, including the infamous Dirty Pipe (CVE-2022-0847) and Baron Samedit (CVE-2021-3156). Once they achieve root-level access, they deploy various implants, including NoodleRAT, Meterpreter, and SPECTRE—a cross-platform backdoor with capabilities that encompass command-and-control functionalities, credential theft, and anti-analysis features.

Financial Exploitation and Use of AI

The BadIIS malware is central to the financial exploitation mechanisms employed by this group. This malware enables the manipulation of web traffic, alters search crawler responses, hijacks content, and injects backlinks that adversely affect search rankings. In earlier assessments, some versions of the BadIIS malware have been classified as commodity malware, shared among Chinese-speaking criminal groups with customizable builders that streamline SEO fraud operations.

What sets UAT-10147 apart is its integration of agentic AI tools. Researchers have uncovered AI-generated playbooks and Python automation that refine various aspects of their exploits and validation processes. The use of tools such as Metasploit, ysoserial, PentestGPT, and DeepAudit significantly reduces the manual tasks typically associated with post-exploitation efforts. This advanced approach permits repeatable intrusions on a considerable scale.

Recommendations for Defense

In light of these developments, cybersecurity experts underscore the critical need for organizations to promptly patch vulnerable web applications. They recommend auditing IIS modules and exclusions in Microsoft Defender, investigating any unexpected scheduled tasks and privileged local accounts, and closely monitoring tools like certutil, PowerShell, and appcmd for any signs of suspicious activity. Furthermore, organizations are urged to review web-server logs for any exploitation attempts relating to the identified CVEs, along with efforts to hunt for unauthorized ASHX handlers and any abnormal behaviors in search-engine crawlers.

In conclusion, the activities of UAT-10147 exemplify the burgeoning sophistication of cybercrime entities. Their strategic application of advanced technologies and systematic targeting of vulnerabilities poses significant challenges for global cybersecurity efforts. As the digital landscape evolves, so too must the defenses devised to safeguard against these persistent threats.

Source link

Latest articles

North Korean Hackers Linked to Rust Supply Chain Attack

North Korean Cyber Threats Exposed in Recent Rust Ecosystem Attack Researchers from Wiz have uncovered...

Quantum Masterclass: Exploring the Overlooked Aspects of Cryptography

IBM's Jai Singh Arun Discusses the Need for Cryptography Risk Mapping Ahead of Quantum...

Backdoored Rust Packages Target Crates.io, Exposing Developers to Build-Time Malware

The Malicious Code Executed During Compilation In a significant security flaw highlighted by researchers, the...

OpenAI Introduces AI Safety Layer to Detect Misuse While Protecting Enterprise Data

OpenAI Enhances AI Safety Measures with New Detection Capabilities In a significant development within the...

More like this

North Korean Hackers Linked to Rust Supply Chain Attack

North Korean Cyber Threats Exposed in Recent Rust Ecosystem Attack Researchers from Wiz have uncovered...

Quantum Masterclass: Exploring the Overlooked Aspects of Cryptography

IBM's Jai Singh Arun Discusses the Need for Cryptography Risk Mapping Ahead of Quantum...

Backdoored Rust Packages Target Crates.io, Exposing Developers to Build-Time Malware

The Malicious Code Executed During Compilation In a significant security flaw highlighted by researchers, the...