Cybercrime Case File
Court Records · Travel · Online Accounts · Fund Flows · Modus Operandi
Independent Information Compilation
ZHU DONG
Subject photograph
Subject Profile / Case Summary

Case File

ZHU DONG
A compilation of public court records, reported information, cybercrime-related allegations and public cybersecurity research
Public Allegations Court Record Available Cybercrime Related
National ID:210623199505080956
Registered residence:辽宁省东港市前阳镇新安村
Current residence:辽宁省丹东市振兴区花园街道城市俪景小区
Page Notice: 本页面为独立资料整理页面,并非 FBI、INTERPOL 或任何政府执法机构官方网站 除明确引用的生效法院裁判内容外,其余“涉嫌”“疑似”“举报”等内容应视为待核实信息,不代表相关司法或安全机构已经作出事实认定
Servers Identified by Court
113 servers
Illegal Control of Computer Information Systems Case
Final Sentence
3 years 6 months
RMB 40,000 fine
TRON Wallet Recorded Inflow
614,814.65
USDT · 2026-03 至 2026-09
Court-Identified Overseas Activity Period
Jul–Sep 2017
Malaysia · Kuala Lumpur
Section 01

Main Alleged Conduct

This section summarizes the principal behavior patterns reflected in final court decisions, public accounts, channel archives, on-chain fund flows and security research
  • Illegal control of computer information systems:A final court decision found that in 2017 Zhu Dong and others searched for vulnerable target servers, implanted malware to obtain control, and uploaded static pages containing gambling keywords and automatic redirects The case involved 113 target servers implanted with malware
  • Gambling advertising and SEO traffic diversion:The court found that one purpose of the conduct was to increase the likelihood that gambling-site advertisements would be indexed or surfaced by search engines and to obtain gambling advertising fees
  • Overseas activity and case location:The judgment states that the relevant persons carried out the conduct from July 2017 at Trillion Apartments in Kuala Lumpur, Malaysia National Immigration Administration records show Zhu Dong left China on 19 June 2017 and entered Beijing on flight D7316 on 27 September 2017, closely matching the activity window described by the court
  • Receipt and transfer of funds:The judgment states that Zhu Dong participated in locating and compromising websites and provided accounts to receive and transfer illicit proceeds This page also records USDT movements involving an associated TRON address to show later fund-flow indicators, while on-chain transfers alone do not constitute a judicial determination that particular funds are criminal proceeds
  • Telegram channel activity indicators:Public messages in a related channel include statements such as “those who can hit foreign sites, come cooperate”, “those with large site networks, come cooperate” and “new Thailand bc route” The page retains the original Telegram message and Wayback and Archive.ph archives for historical verification
  • GitHub and online-account indicators:The page records public information including a GitHub account, historical Telegram usernames and a T00ls member profile for account correlation and historical tracking Stable identifiers such as the GitHub User ID can be used to verify the same platform account after a username changes
  • Technical similarity to later security research:Public security research describing IIS server compromise, SEO poisoning, malicious redirects and monetization of gambling traffic shows technical patterns similar to some methods recorded in the 2017 final judgment
Section 02

Potentially Relevant Legal Provisions by Jurisdiction

Country / Region Potential Offenses Legal Basis
ChinaIllegal access to computer information systems, operating gambling activities, money launderingPRC Criminal Law Articles 285, 286, 303 and 191
United States (Five Eyes)Unauthorized computer access, computer fraud, money laundering, wire fraud18 U.S.C. §1030、§1956、§1343
United Kingdom (Five Eyes)Unauthorized computer access, computer intrusion to commit or facilitate further offenses, unauthorized interference with computers, money launderingComputer Misuse Act 1990 §§1–3;Proceeds of Crime Act 2002(Part 7)
Canada (Five Eyes)Unauthorized use of computers, dealing with or transferring proceeds of crime, money launderingCriminal Code, R.S.C. 1985, c. C-46, §§342.1、462.31
Australia (Five Eyes)Unauthorized access to or modification of restricted data, impairment of data or electronic communications, dealing with proceeds of crime and money launderingCriminal Code Act 1995, Part 10.7(Divisions 477–478);Division 400
New Zealand (Five Eyes)Accessing computer systems for dishonest purposes, interfering with computer systems, money launderingCrimes Act 1961, §§243、249–250
European UnionPotential violations of anti-money-laundering and data-protection rulesFifth Anti-Money Laundering Directive (5AMLD), GDPR where applicable
Section 03

Identity Information and Online Accounts

Identity and Contact Information
NameZHU DONG
Sex / EthnicityMale / Han Chinese
Date of birth1995-05-08
Height / Foot length180 cm / 26 cm
Occupation / statusUnemployed
Phone Numbers13118173713 / 15641571506 / 17641506115
AddressBuilding 13, Chengshi Lijing Community, Huayuan Subdistrict, Zhenxing District, Dandong, Liaoning, China
Online Accounts and Platform Identities
GitHub Account CODE @ggmmoo9123
GitHub User ID:57856611
Node ID:MDQ6VXNlcjU3ODU2NjEx
Account Created:2019-11-17 07:27:24 UTC
Public Repositories:11
Stable API Identifier:api.github.com/user/57856611
T00ls Account SECURITY Username:芙蓉王jh
Profile:cn.t00ls.com/members-profile-6925.html
This member profile redirects unauthenticated visitors to the login page
WeChat Account WECHATWeChat ID:xiaodongdong518
Telegram Accounts TELEGRAM Account A: @shenji518233(display name: 518)
Telegram ID:6551946770
Hong Kong phone number:+852 6*** 7047 (associated indicator involving the Telegram account named “518”)
Account B: @apt25
Telegram ID:992261040

Account profile A · @shenji518233

Telegram ID 6551946770

Current display:@shenji518233 · 名称 518
Historical characteristics:已记录 7 个曾用用户名,2024—2026 年间多次更换用户名
Naming link:“518”同时出现在 Telegram 显示名、当前/历史用户名及微信号 xiaodongdong518 中
Contact indicator:与香港手机号 +852 6*** 7047 存在关联记录
★ Profile summary:账号呈现持续更换公开用户名、但反复保留“518”命名元素的特征,固定 Telegram ID 可用于跨用户名追踪同一账号
画像仅基于页面已记录的用户名历史、固定 Telegram ID、命名重复和联系方式关联进行概括

Account profile B · @apt25

Telegram ID 992261040

Current display:@apt25
Historical characteristics:曾使用 @apt46、@apt002、@null1ll、@apt28、@tools_none、@system1ock 等用户名
Naming tendency:多个曾用名带有 APT、tools、system 等技术/安全语义元素
Hacking / penetration testingWebShellSEO / traffic acquisitionGamblingData resourcesUSDT / paymentsOverseas resources
★ Profile summary:账号的用户名轨迹和已检出群组主题整体偏向网络安全、渗透、站点控制、SEO 引流、博彩、数据资源、支付及境外资源等技术与业务交叉领域
★ Telegram-related group categories:
Hacking / penetration / WebShell / vulnerability techniques SEO / traffic acquisition / site networks Gambling / Sportsbook / Casino Data / social-engineering databases / gray-black market resources Payment channels / USDT / cryptocurrency Southeast Asia / overseas expansion / international resources Encrypted communications / VPN / technical tools Blockchain / mining pools / exchanges
按 tgscanrobot-apt25 数据中的群组名称与主题进行属性归类,仅保留类别层级,不展开具体群组名单

Related Telegram channel: @chapasswords(channel display name: passwords)
Public channel content summary:该频道公开发布数据库查询、套餐购买、查询升级、境外站点合作及 WebShell 资源合作等内容
Key channel quotes:
“Those who can hit foreign sites, come cooperate; those with large site networks, come cooperate; those who can continuously obtain sites, come cooperate; no need to give me access”
“New Thailand bc route opened, cooperate and take off together”
2026-08-24 · New message #39:
“收webshell”
“1.site没被锁过的”
“2.全球除中国以外的gov/edu,php/asp/aspx;java不要”
“3.根目录有权限;服务器权限加钱”
“4.给了shell后能移垫并权限,能长期合作,每天有产出的优先”
New message #40 (captured 2026-09-09):
“收webshell”
“1.site没被做过的,有收录的”
“2.全球除中国以外的gov/edu,php/asp/aspx都可以;java不要”
“3.根目录有权限;服务器权限加钱”
“4.给了shell后能够维护权限,能长期合作,每天有产出的优先”
The excerpts above cover @chapasswords messages #38, #39 and #40, with original Telegram links and available mirror entries retained for historical checking
Gambling / Traffic-Diversion Business Indicators
Gambling / Traffic-Diversion Platforms and Business Indicators Recorded sites: M358(www.m35813.com) · U31(www.u31ww.com) · POP777B(pop777b.co) · PG99(pg99st186.xyz) · UFA9Y(ufa9y.vip)
Brand / platform indicators:POP777B、PG99、UFA9Y 被列入本页面现有整理材料中的关联品牌 / 平台与跳转目标线索
Business indicators:Telegram 频道公开内容中出现“新开泰国bc线路”“能打国外站的来合作”“手上有大量站群的来合作”“长期能搞站的来合作”,并在 #39 中新增收购 WebShell、境外 gov/edu 站点、根目录权限及服务器权限等合作条件
Associated pattern:结合生效裁判中已经确认的赌博关键词、自动跳转及搜索引擎导流行为,本页面将相关站点、站群合作、境外线路、跳转脚本及SEO导流统一归入博彩 / 引流业务线索进行整理
Section 04

TRON Wallet and Fund Flows

Associated TRON address: TZ•••••••••••••••••••••••••••••••••
Data period:2026-03-17 至 2026-09-04(UTC)
Total USDT Inflow614,814.65 USDT
Total USDT Outflow530,603.50 USDT
Net Inflow84,211.15 USDT
USDT Transfers327 笔

Fund-flow characteristics:During the observed period, this address continuously received and sent USDT, with frequent activity, multiple upstream sources and multiple downstream distributions The overall pattern is more consistent with an active receiving, settlement or intermediary wallet than a long-term static holding address Only aggregate data are shown and specific addresses and transaction hashes are masked

Section 05

Passport and National ID Information

Document TypeDocument NumberValid UntilStatusIssuing Place
Ordinary PassportE740412112026-05-10Inactive辽宁省丹东市
Resident Identity Card210623199505080956Long-termValidQianyang Town, Donggang, Liaoning, China
Section 06

Entry and Exit Records

Source:National Immigration Administration “Entry and Exit Record Query Result (Electronic File)” The “Overseas Country / Location (flight-based inference)” column is not an original immigration-record field and is inferred from public route information for the flight number and the entry/exit direction for context
No Exit / Entry Date Document Document Number Port of Entry / Exit Flight Overseas Country / Location (flight-based inference)
1Entry2017-09-27Ordinary PassportE74041211Beijing Capital AirportD7316Malaysia · Kuala Lumpur (KUL)
2Exit2017-06-19Ordinary PassportE74041211Beijing Capital Airport5J673Philippines · Manila (MNL)
3Entry2017-03-27Ordinary PassportE74041211Shenzhen AirportAK128Malaysia · Kuala Lumpur (KUL)
4Exit2016-12-29Ordinary PassportE74041211Shanghai Pudong AirportFM861Malaysia · Kuala Lumpur (KUL)
5Entry2016-06-23Ordinary PassportE74041211Shanghai Pudong AirportFM862Malaysia · Kuala Lumpur (KUL)
6Exit2016-05-24Ordinary PassportE74041211Shanghai Pudong AirportFM861Malaysia · Kuala Lumpur (KUL)

Query range:1 January 2007 to 21 August 2026 The electronic file notes that records may contain errors or omissions caused by data collection, transmission or processing
Flight-location note:Public route information maps D7316 to Kuala Lumpur → Beijing, 5J673 to Beijing → Manila, AK128 to Kuala Lumpur → Shenzhen, and FM861/FM862 to Shanghai Pudong ↔ Kuala Lumpur Therefore the added country/location column shows the overseas endpoint of the corresponding flight rather than a field contained in the immigration document

Section 07

Overall Case and Public Activity Timeline

2016-05-24
First visible departure toward Kuala LumpurDeparted from Shanghai Pudong on FM861, whose overseas endpoint corresponds to Kuala Lumpur
2016-12-29
Second departure toward Kuala LumpurDeparted from Shanghai Pudong on FM861
2017-03-27
Returned to China from the Kuala Lumpur directionEntered Shenzhen on AK128
Jul–Sep 2017
Court-identified Kuala Lumpur offense periodThe judgment records server searching, malware implantation, server control and gambling SEO / automatic redirect activity at Trillion Apartments, involving 113 target servers by the end of September
2017-11-28
ArrestedThe judgment states that Zhu Dong was arrested in Dandong, Liaoning
2017-11-30
Criminal-detention admission record新增截图资料显示入所日期为2017-11-30,入所原因为“刑事拘留”,案件类别记载为“非法侵入计算机信息系统案”
2019-09-16
Final appellate rulingNanjing Intermediate People’s Court issued Criminal Ruling (2019) Su 01 Xing Zhong No 768, affirming the original judgment
2019-10-16
★ Transfer to prison新增记录显示出所日期为2019-10-16,司法结果为“有期徒刑”,出所原因为“投送监狱”,该节点表示从看守所转送监狱继续执行刑罚,并非刑满释放
Around 2021-05
★ Estimated sentence completion按2017-11-28被抓获并计入羁押折抵、有期徒刑3年6个月推算,在不存在减刑、假释或其他影响刑期因素的情况下,预计刑满释放时间约为2021年5月下旬至月底,此日期属于依据现有判决与羁押时间作出的推算,并非实际释放记录
2019-11-17
GitHub account createdThe GitHub account associated with User ID 57856611 was created on this date
2022—2026
Telegram usernames changed over timeBoth account records show multiple historical username changes spanning 2022 to 2026
Mar–Aug 2026
High-frequency TRON / USDT activity页面收录的钱包汇总显示统计期内有614,814.65 USDT流入、530,603.50 USDT流出,共308笔USDT流水
2026-08-21
Telegram 消息 #38 留存@chapasswords 的站群、境外站点合作及“泰国bc线路”等公开内容已保留 Telegram 原消息、Wayback Machine 与 Archive.ph 存档入口
2026-08-24
Telegram 消息 #39 更新@chapasswords 新增“收webshell”及境外 gov/edu、根目录权限、服务器权限和长期合作条件等公开内容,并同步保留 Wayback Machine 与 Archive.ph 镜像
Section 08

Court Judgment × Entry/Exit Record Cross-Check Timeline

本时间线将国家移民管理局出入境记录与(2019)苏01刑终768号裁定书中涉及祝东的时间、地点信息并列展示 “航班境外端点”来自公开航线资料推定;法院事实以裁判文书中的认定为准

National Immigration Administration Record Court Finding Cross-Check Match
2016-05-24
Immigration Record

Exited through Shanghai Pudong Airport using ordinary passport E74041211 on flight FM861 Public route information places the overseas endpoint in Kuala Lumpur, Malaysia (KUL)

2016-06-23
Immigration Record

Entered through Shanghai Pudong Airport on flight FM862 Public route information corresponds to Kuala Lumpur (KUL) → Shanghai Pudong

2016-12-29
Immigration Record

Exited through Shanghai Pudong Airport on flight FM861, with the overseas endpoint corresponding to Kuala Lumpur, Malaysia (KUL)

2017-03-27
Immigration Record

Entered through Shenzhen Airport on flight AK128 Public route information corresponds to Kuala Lumpur (KUL) → Shenzhen

2017-06-19
Immigration Record

Exited through Beijing Capital Airport on flight 5J673 Public route information corresponds to Beijing → Manila, Philippines (MNL) Chinese entry/exit records do not show subsequent flight segments occurring entirely outside China

Starting July 2017
Court Finding

Criminal Ruling (2019) Su 01 Xing Zhong No 768 found that Zhang Junjie, Peng Linglong, Zhu Dong and Jiang Yuhao acted pursuant to prior agreement at Unit 902, Block B, Trillion Apartments in Kuala Lumpur, Malaysia, illegally controlling vulnerable target servers and uploading static pages containing gambling keywords and automatic redirects

2017-06-19 → 2017-09-27
Cross-check Match

The court-identified “activity in Kuala Lumpur beginning in July 2017” falls entirely within the window between this departure and re-entry: departure from China before July and re-entry on 27 September

2017-09-27
Immigration Record

Entered through Beijing Capital Airport on flight D7316 Public route information corresponds to Kuala Lumpur, Malaysia (KUL) → Beijing (PEK)

End of September 2017
Cross-check Match

The judgment states that by the end of September 2017, the four defendants had connected to 113 target servers implanted with malware Zhu Dong entered Beijing from the Kuala Lumpur direction on 27 September, closely matching the ending phase of the overseas activity described in the judgment

2017-11-28
Court Finding

The judgment states that Zhu Dong was arrested in Zhenxing District, Dandong, Liaoning, roughly two months after the 27 September 2017 entry record and consistent with his having returned to China

2019-09-16
Final Ruling

Nanjing Intermediate People’s Court issued the final ruling (2019) Su 01 Xing Zhong No 768, dismissing the appeal and affirming the original judgment Zhu Dong was sentenced to three years and six months imprisonment and fined RMB 40,000 for illegally controlling computer information systems

Cross-check conclusion:The available materials support the following timeline: Zhu Dong left China on 19 June 2017, the court-identified Kuala Lumpur activity began in July 2017, he entered Beijing on 27 September 2017 on flight D7316 whose overseas endpoint was Kuala Lumpur, and he was arrested in Dandong, Liaoning on 28 November 2017 The two sets of records align closely on the key time window and the Kuala Lumpur location

Entry/exit source:National Immigration Administration “Entry and Exit Record Query Result (Electronic File)”, covering 2007-01-01 to 2026-08-21
Court source:Jiangsu Nanjing Intermediate People’s Court Criminal Ruling (2019) Su 01 Xing Zhong No 768 The later “Final Judgment” section also links to Supreme People’s Court Guiding Case No 145

Section 09

Criminal Conduct Confirmed by Final Judgment

Final appellate case number:(2019) Su 01 Xing Zhong No 768 · Nanjing Intermediate People’s Court, Jiangsu
Case:Zhang Junjie, Peng Linglong, Zhu Dong and Jiang Yuhao — Illegal Control of Computer Information Systems
New case / detention record information readable from the screenshot
Detention entry date★ 重点2017-11-30
Reason for detentionCriminal detention
Case category★ 对应非法侵入计算机信息系统案
Year of legal document2018年
Detention exit date★ 节点2019-10-16
Judicial result★ 重点Fixed-term imprisonment
Reason for exit★ 重点Transferred to prison
Identity information男,汉族,1995-05-08出生,身高180 cm,足长26 cm,身份栏记载“无业人员”
Brief case description★ 手法对应记录显示某省政府官网服务器遭攻击并留下后门程序

★ Judgment × detention-record cross-analysis

★ Timeline matchEntered detention two days after arrest终审裁判记载 2017-11-28 在辽宁丹东被抓获,新增记录显示 2017-11-30 因刑事拘留入所,两个节点前后仅相隔 2 天
★ 手法对应Server attack and backdoor program生效裁判确认检索存在漏洞的服务器、植入木马并取得控制权限,新增记录则概括记载某省政府官网服务器遭攻击并留下后门程序,两份材料在服务器入侵与持续控制这一行为模式上具有明显对应
★ Legal wording should be distinguishedCase category differs from final offense新增记录的案件类别写作“非法侵入计算机信息系统案”,终审裁判最终认定为“非法控制计算机信息系统罪”,页面将两种原始表述并列保留,不将其改写成同一罪名
★ Detention milestoneTransferred to prison after final judgment南京市中级人民法院于 2019-09-16 作出终审裁定,新增记录显示 2019-10-16 出所,司法结果为“有期徒刑”,出所原因为“投送监狱”,说明该日是由看守所转送监狱继续服刑的执行节点,而不是刑满释放
★ Estimated sentence completionAround late May 2021以2017-11-28被抓获时间作为羁押折抵起点,并按生效判决确定的3年6个月有期徒刑计算,若无减刑、假释或其他影响刑期的情形,预计刑满释放时间约在2021年5月27日至28日前后,页面以“约2021年5月下旬”作为保守展示,该日期不是已确认的实际释放日期
Controlled Servers
113 servers
Zhu Dong Sentence
3 years 6 months
Fine
RMB 40,000
Disgorged Illegal Proceeds
RMB 25,000

最高人民法院指导案例145号《张竣杰等非法控制计算机信息系统案》记载: 祝东与其他被告人事先共谋,为赚取赌博网站广告费用,检索存在防护漏洞的目标服务器, 植入木马程序取得控制权限,并上传含赌博关键词及自动跳转功能的静态网页, 以提高赌博网站广告被搜索引擎命中的概率

Zhu Dong Final Judgment Information
Final Appellate Case Number(2019) Su 01 Xing Zhong No 768
Offense Confirmed by Final JudgmentIllegal Control of Computer Information Systems
SentenceThree years and six months imprisonment
FineRMB 40,000
Disgorged Illegal ProceedsRMB 25,000
Relevant Legal ProvisionsPRC Criminal Law Article 285 paragraphs 1 and 2
Judgment StatusAppeal dismissed, original judgment affirmed, ruling final

Judicial source: Supreme People’s Court Guiding Case No 145 (approved by the Supreme People’s Court Adjudication Committee and published on 29 December 2020)

Section 10

Modus Operandi / Operational Analysis

Core method confirmed by the court:The 2017 final judgment confirmed that the relevant persons searched for and screened vulnerable target servers, implanted malware to obtain control, then uploaded static pages containing gambling keywords and automatic redirects to improve gambling-ad visibility in search engines and obtain advertising revenue
Method profile based on the public security research:Talos、Elastic、Unit 42、加拿大网络安全中心、SOC Prime 与 Gurucul 的公开研究显示,近年的相关生态已经从早期“控制服务器后植入关键词和跳转页面”,演变为更系统化的批量漏洞利用 → Web Shell / 后门驻留 → 权限提升与防护规避 → IIS / BadIIS 植入 → 搜索引擎欺骗与访客分流 → 博彩、诈骗等流量变现 → 数据窃取与长期控制 → 自动化、AI辅助扩展model
STEP 01Target screening at scaleHigh-authority websites and internet-exposed servers
STEP 02Vulnerability exploitation / Web ShellObtain remote command execution and site control
STEP 03Persistence and privilege escalationBackdoors, accounts, services or remote-control components
STEP 04Defense evasionHide malicious components and prolong access
STEP 05BadIIS / Traffic controlIntercept IIS request processing and page output
STEP 06SEO poisoning / CloakingServe different content to crawlers and normal visitors
STEP 07Gambling and malicious redirectsRedirect search traffic to designated landing pages
STEP 08Data theft / resource reuseCollect configurations, credentials, source code and other site resources
STEP 09Automation and AI assistanceScanning, validation, payload generation and scaled operations
STEP 10Cooperation and settlementSite-network cooperation, overseas routes and USDT transfers
Method chain summarized from public research
StageMain techniques described in public researchPurpose / EffectSources
1 · Target acquisition at scale大规模搜集互联网暴露网站与服务器,优先利用已公开漏洞、配置弱点或可上传 Web Shell 的入口快速扩大可控制服务器数量,并优先利用政府、教育、企业等原本具有较高搜索信誉的域名Talos UAT-10147、UAT-8099;Elastic REF4033
2 · Initial access通过远程代码执行、文件上传缺陷、Web Shell 或既有后门获得命令执行与文件修改能力取得对网站目录、IIS 配置和服务器环境的操作权限Talos UAT-10147 / UAT-8099;加拿大 SharpViewStateKing
3 · Reconnaissance and environment discovery识别 IIS 站点、虚拟目录、权限、运行账号、系统版本及可写路径,并判断后续可植入位置选择最稳定的持久化方式,并发现同一服务器上的更多网站资源Talos UAT-10147;加拿大 SharpViewStateKing
4 · Persistence and privilege escalation创建额外账号、部署远程控制组件、计划任务、服务或长期 Web Shell,并尝试获得更高系统权限即使原始漏洞被修复,也能继续控制服务器并重复利用其网站资源Talos UAT-10147 / SPECTRE / UAT-8099; Elastic REF4033
5 · Defense evasion通过修改安全配置、排除特定目录、混淆组件或采用更低检测率的模块来降低被安全软件发现的概率延长驻留时间,为后续 SEO 欺诈、流量劫持和数据窃取提供稳定环境Talos UAT-10147 / SPECTRE; Elastic REF4033; Canadian SharpViewStateKing research
6 · IIS / BadIIS implantation把恶意 IIS 模块、ASP.NET 处理器、PHP 脚本或其他流量控制组件嵌入服务器请求链不必修改正常页面主体,也能在服务器层面对进入与返回的 HTTP 流量进行判断、替换或转发SOC Prime / Talos BadIIS;Unit 42 Operation Rewrite;Elastic REF4033
7 · Search-engine deception根据 User-Agent、Referer、URL 关键词等条件识别搜索引擎爬虫,为爬虫动态提供大量关键词页、垃圾链接或远端生成的 SEO 内容借用被入侵合法网站的域名信誉,让攻击者指定的关键词更容易进入搜索结果Unit 42 Operation Rewrite;Talos UAT-8099;Elastic REF4033
8 · Cloaking and visitor segmentation对搜索爬虫与普通访客返回不同内容:爬虫看到关键词页面,真实用户从搜索结果进入后则被重定向或代理到其他页面隐藏真实用途,同时把自然搜索流量转换成博彩、色情、诈骗或其他付费落地页流量Unit 42 Operation Rewrite;Talos UAT-8099;Elastic REF4033
9 · JavaScript / page-level redirects除服务器级 BadIIS 外,也可通过 JavaScript、ASP.NET 或 PHP 等更轻量方式部署跳转逻辑;本页面已收录的 nb.jsvnnb.js 即属于直接将访客送往指定域名的脚本形式快速替换推广目标,便于不同品牌、线路或渠道之间切换Gurucul IOC;本页面收录的公开 JS 样本;SOC Prime / Talos builder 研究
10 · Data and server-resource reuse部分活动除 SEO 欺诈外还会收集网站源码、配置、凭据、证书或系统信息,并利用同一服务器继续发现更多站点扩大可继续入侵或变现的资产范围,同时为后续权限维持与横向操作提供材料Unit 42 Operation Rewrite;Talos UAT-8099 / UAT-10147;加拿大 SharpViewStateKing
11 · Automation and AI assistance将漏洞验证、环境侦察、载荷生成、部署检查和故障排查脚本化,Talos 还观察到 AI 工具被用于生成和验证部分入侵工作流降低单个目标所需人工时间,使同一套流程更容易复制到大量服务器Talos UAT-10147 / SPECTRE
12 · Site-network cooperation and monetization把被控制的网站视作可持续运营的“站群 / 流量资源”,通过即时通讯渠道寻找网站、权限、线路或推广合作,并结合加密资产进行结算将技术入侵、站点控制、流量运营与商业变现拆分为可重复的合作链条本页面 Telegram 存档、TRON 流水与法院既有获利模式记录
Overall method profile:
批量筛选互联网暴露目标 → 利用漏洞或 Web Shell 获得服务器权限 → 枚举 IIS 与网站环境 → 建立长期驻留并提升权限 → 规避安全软件 → 植入 BadIIS / ASP.NET / PHP / JavaScript 流量控制组件 → 针对搜索引擎爬虫投放关键词和 SEO 内容 → 对真实访客实施跳转、反向代理或页面替换 → 将流量导向博彩及其他付费落地页 → 收集源码、配置或凭据并复用更多站点 → 通过自动化和 AI 辅助扩大操作规模 → 以站群合作和加密资产结算完成持续变现

这些公开研究共同体现的核心并不是单一“挂跳转页面”,而是把已经具有信誉和搜索权重的正常网站变成可长期控制的流量基础设施:前端表现为 SEO 关键词、搜索结果污染和跳转,后端则包含权限维持、IIS 模块植入、服务器资源复用、数据收集和批量自动化
Profit / Monetization Model:从法院已经确认的赌博广告获利模式,到公开安全研究反复记录的 SEO 流量劫持、博彩与诈骗落地页导流,再结合页面收录的站群合作信息与 USDT 资金流,整体可概括为“控制有搜索权重的网站 → 获取自然搜索流量 → 按推广、广告或合作方式导向付费落地页 → 复用站群与服务器资源 → 通过加密资产或其他渠道结算”
Profit / Monetization Chain Summary
Monetization stageMethodRevenue source / commercial valueBasis on this page
1 · Gambling advertising fees控制服务器后植入赌博关键词、自动跳转页面,提高赌博广告在搜索引擎中的命中率按广告展示、点击、导流或合作约定获取费用生效裁判已明确记载“为赚取赌博网站广告费用”
2 · SEO traffic monetization利用正常网站已有的域名信誉与搜索权重生成关键词页、垃圾链接或动态 SEO 内容,再将真实访客送往指定落地页把原本属于正常网站的搜索流量转换为可出售、可分成或可计费的推广流量Talos、Elastic、Unit 42 等公开研究
3 · Gambling / scam landing-page traffic diversion通过 BadIIS、反向代理、JavaScript、ASP.NET 或 PHP 跳转,将访客导向博彩、诈骗或其他商业落地页按流量、注册、充值、转化或渠道合作模式产生收益公开安全研究;页面收录的 nb.jsvnnb.js 跳转样本
4 · Site-network / access-resource cooperation将已控制网站、站群、服务器权限和境外线路作为可重复使用的资源,与其他推广方或技术方合作通过出租、合作分成、代投放或按站点/线路收费实现变现页面收录的 Telegram 频道公开存档
5 · Server-resource reuse在同一服务器继续枚举更多站点、复用源码、配置、凭据或现有权限,将一次入侵扩展为多个可运营资产降低新增站点的获取成本,提高单台服务器的持续产出价值Talos、Unit 42、加拿大网络安全中心等公开研究
6 · Automation at scale把目标发现、漏洞验证、部署、跳转规则和故障排查脚本化,并利用自动化或 AI 辅助扩大操作数量降低人工成本,使同类流量资产能够批量复制和持续运营Talos UAT-10147 等公开研究
7 · Fund settlement合作收益通过传统账户或加密资产进行接收、转移和分流;页面收录的 TRON 地址表现为持续 USDT 收付用于跨境、快速或多方合作结算裁判中的账户接收 / 转移赃款记录;页面 TRON / USDT 汇总
Monetization flow at a glance:
拿到网站或服务器权限 → 借用域名权重做 SEO → 从搜索引擎获取自然流量 → 根据访客来源实施 Cloaking / 跳转 → 导向博彩或其他付费页面 → 按广告、流量、注册、充值或合作分成获利 → 继续复用站群与服务器资源 → 通过账户或 USDT 等方式完成结算

Research basis:本节技术画像依据页面“公开安全研究与关联说明”中列出的 Cisco Talos、Elastic Security Labs、Palo Alto Networks Unit 42、加拿大网络安全中心、SOC Prime 与 Gurucul 公开研究进行归纳;其中各研究描述的是对应威胁活动或恶意软件生态,本节用于总结技术模式,不把不同研究中的活动主体自动视为同一行为人

Section 11

Public Security Research and Related Analysis

下列安全机构公开报告记录了近年来针对 IIS 服务器的大规模入侵、BadIIS 恶意模块部署、搜索引擎优化(SEO)投毒及向赌博、色情或加密货币诈骗网站 重定向流量等活动这些技术与最高人民法院指导案例145号所记载的服务器控制、 赌博关键词植入及自动跳转行为存在模式上的相似之处

Public Security Research Summary
PublisherResearch TopicKey FindingsSource
SOC Prime / Cisco Talos BadIIS Commodity Malware Ecosystem The report states that multiple Chinese-speaking cybercrime operators use BadIIS against IIS servers for SEO manipulation, malicious traffic redirects, reverse proxying and outbound-link injection, with related activity continuing from at least 2021 into early 2026 View Report
Cisco Talos From PDB strings to MaaS: Commodity BadIIS ecosystem Talos reported on May 19, 2026 that a demo.pdb-identified BadIIS variant and its builder were likely sold or shared as commodity malware among multiple Chinese-speaking cybercrime groups The builder can generate configuration files, JavaScript redirectors and PHP backlink scripts, and supports traffic redirection, reverse proxying, content hijacking, and internal / external link injection for SEO fraud View Talos Article
Elastic Security Labs REF4033 Global SEO Poisoning Campaign The report states that more than 1,800 Windows servers were affected across government, education and enterprise victims Compromised servers were used to redirect traffic to gambling sites and cryptocurrency scam pages, and the activity was assessed as consistent with UAT-8099 View Report
Palo Alto Networks Unit 42 Operation Rewrite / CL-UNK-1037 Researchers assessed with high confidence, based on language, infrastructure and code characteristics, that the activity was operated by Chinese speakers, and identified infrastructure and architectural overlap with Group 9 The report also noted only limited similarities with DragonRank View Report
Canadian Centre for Cyber Security SharpViewStateKing Implant Framework The report analyzes an incident involving SharpViewStateKing, Godzilla and BadIIS, covering web-server control, privilege escalation, remote execution, credential theft and lateral movement View Report
Gurucul UAT-10147 / SPECTRE threat research Gurucul's August 24, 2026 research describes UAT-10147 as a Chinese-speaking intrusion operation targeting IIS and Linux servers Its IOC list directly includes https://js.jyzyps.com/js/vnnb.js and https://js.jyzyps.com/js/nb.js, together with additional domains, IP addresses and file hashes associated with the activity View Report
RedQueen / TJ-UN Threat-intelligence detail entry Included as an additional cross-reference for the security-research materials collected on this page View Intelligence Entry
Cisco Talos UAT-10147 / SPECTRE cross-platform implant Talos reported on August 20, 2026 that SPECTRE is a cross-platform backdoor with a Linux kernel-level Specter rootkit The research documents Windows and Linux persistence, process injection, credential theft, anti-analysis and defense-evasion capabilities, including Windows BYOVD-based EDR bypass and Linux rootkit hiding / privilege escalation The same research also describes BadIIS and an ASHX SEO engine used for search-engine manipulation and malicious JavaScript delivery View Talos Article
Cisco Talos UAT-10147: Agentic AI in post-compromise operations Talos reported on August 20, 2026 that UAT-10147 targeted Windows and Linux web servers globally using publicly disclosed vulnerabilities, automated reconnaissance, payload generation and persistence workflows The report also documents deployment of BadIIS and SPECTRE components, SEO fraud and data theft View Report
Cisco Talos UAT-8099 Chinese-Speaking Cybercrime Group Talos identified and began tracking UAT-8099 in April 2025 The group targeted high-value IIS servers in India, Thailand, Vietnam, Canada and Brazil, using Web Shells, RDP, Cobalt Strike and multiple BadIIS samples to maintain control and conduct SEO fraud, while stealing credentials, configuration files and certificate data Compromised servers also redirected users to unauthorized advertising or illegal gambling sites View Report