Exited through Shanghai Pudong Airport using ordinary passport E74041211 on flight FM861 Public route information places the overseas endpoint in Kuala Lumpur, Malaysia (KUL)
Main Alleged Conduct
- Illegal control of computer information systems:A final court decision found that in 2017 Zhu Dong and others searched for vulnerable target servers, implanted malware to obtain control, and uploaded static pages containing gambling keywords and automatic redirects The case involved 113 target servers implanted with malware
- Gambling advertising and SEO traffic diversion:The court found that one purpose of the conduct was to increase the likelihood that gambling-site advertisements would be indexed or surfaced by search engines and to obtain gambling advertising fees
- Overseas activity and case location:The judgment states that the relevant persons carried out the conduct from July 2017 at Trillion Apartments in Kuala Lumpur, Malaysia National Immigration Administration records show Zhu Dong left China on 19 June 2017 and entered Beijing on flight D7316 on 27 September 2017, closely matching the activity window described by the court
- Receipt and transfer of funds:The judgment states that Zhu Dong participated in locating and compromising websites and provided accounts to receive and transfer illicit proceeds This page also records USDT movements involving an associated TRON address to show later fund-flow indicators, while on-chain transfers alone do not constitute a judicial determination that particular funds are criminal proceeds
- Telegram channel activity indicators:Public messages in a related channel include statements such as “those who can hit foreign sites, come cooperate”, “those with large site networks, come cooperate” and “new Thailand bc route” The page retains the original Telegram message and Wayback and Archive.ph archives for historical verification
- GitHub and online-account indicators:The page records public information including a GitHub account, historical Telegram usernames and a T00ls member profile for account correlation and historical tracking Stable identifiers such as the GitHub User ID can be used to verify the same platform account after a username changes
- Technical similarity to later security research:Public security research describing IIS server compromise, SEO poisoning, malicious redirects and monetization of gambling traffic shows technical patterns similar to some methods recorded in the 2017 final judgment
Potentially Relevant Legal Provisions by Jurisdiction
| Country / Region | Potential Offenses | Legal Basis |
|---|---|---|
| China | Illegal access to computer information systems, operating gambling activities, money laundering | PRC Criminal Law Articles 285, 286, 303 and 191 |
| United States (Five Eyes) | Unauthorized computer access, computer fraud, money laundering, wire fraud | 18 U.S.C. §1030、§1956、§1343 |
| United Kingdom (Five Eyes) | Unauthorized computer access, computer intrusion to commit or facilitate further offenses, unauthorized interference with computers, money laundering | Computer Misuse Act 1990 §§1–3;Proceeds of Crime Act 2002(Part 7) |
| Canada (Five Eyes) | Unauthorized use of computers, dealing with or transferring proceeds of crime, money laundering | Criminal Code, R.S.C. 1985, c. C-46, §§342.1、462.31 |
| Australia (Five Eyes) | Unauthorized access to or modification of restricted data, impairment of data or electronic communications, dealing with proceeds of crime and money laundering | Criminal Code Act 1995, Part 10.7(Divisions 477–478);Division 400 |
| New Zealand (Five Eyes) | Accessing computer systems for dishonest purposes, interfering with computer systems, money laundering | Crimes Act 1961, §§243、249–250 |
| European Union | Potential violations of anti-money-laundering and data-protection rules | Fifth Anti-Money Laundering Directive (5AMLD), GDPR where applicable |
Identity Information and Online Accounts
GitHub User ID:57856611
Node ID:MDQ6VXNlcjU3ODU2NjEx
Account Created:2019-11-17 07:27:24 UTC
Public Repositories:11
Stable API Identifier:api.github.com/user/57856611
Profile:cn.t00ls.com/members-profile-6925.html
This member profile redirects unauthenticated visitors to the login page
Telegram ID:6551946770
Hong Kong phone number:+852 6*** 7047 (associated indicator involving the Telegram account named “518”)
查看账号线索 A 的历史用户名(7 个)
@sanmaogege233(2026-04-15)
@fan13462s(2024-03-25)
@kalong462(2024-03-11)
@fan13462(2024-02-27)
@fankalong(2024-02-21)
@fankalong462(2024-02-20)
Telegram ID:992261040
View historical usernames for Account B (6)
@apt002(2025-03-31)
@null1ll(2024-05-13)
@apt28(2024-03-25)
@tools_none(2022-08-03)
@system1ock(2022-05-22)
Account profile A · @shenji518233
Current display:@shenji518233 · 名称 518
Historical characteristics:已记录 7 个曾用用户名,2024—2026 年间多次更换用户名
Naming link:“518”同时出现在 Telegram 显示名、当前/历史用户名及微信号 xiaodongdong518 中
Contact indicator:与香港手机号 +852 6*** 7047 存在关联记录
Account profile B · @apt25
Current display:@apt25
Historical characteristics:曾使用 @apt46、@apt002、@null1ll、@apt28、@tools_none、@system1ock 等用户名
Naming tendency:多个曾用名带有 APT、tools、system 等技术/安全语义元素
Hacking / penetration / WebShell / vulnerability techniques SEO / traffic acquisition / site networks Gambling / Sportsbook / Casino Data / social-engineering databases / gray-black market resources Payment channels / USDT / cryptocurrency Southeast Asia / overseas expansion / international resources Encrypted communications / VPN / technical tools Blockchain / mining pools / exchanges
按 tgscanrobot-apt25 数据中的群组名称与主题进行属性归类,仅保留类别层级,不展开具体群组名单
Related Telegram channel: @chapasswords(channel display name: passwords)
Public channel content summary:该频道公开发布数据库查询、套餐购买、查询升级、境外站点合作及 WebShell 资源合作等内容
“Those who can hit foreign sites, come cooperate; those with large site networks, come cooperate; those who can continuously obtain sites, come cooperate; no need to give me access”
“New Thailand bc route opened, cooperate and take off together”
“收webshell”
“1.site没被锁过的”
“2.全球除中国以外的gov/edu,php/asp/aspx;java不要”
“3.根目录有权限;服务器权限加钱”
“4.给了shell后能移垫并权限,能长期合作,每天有产出的优先”
“收webshell”
“1.site没被做过的,有收录的”
“2.全球除中国以外的gov/edu,php/asp/aspx都可以;java不要”
“3.根目录有权限;服务器权限加钱”
“4.给了shell后能够维护权限,能长期合作,每天有产出的优先”
Brand / platform indicators:POP777B、PG99、UFA9Y 被列入本页面现有整理材料中的关联品牌 / 平台与跳转目标线索
Business indicators:Telegram 频道公开内容中出现“新开泰国bc线路”“能打国外站的来合作”“手上有大量站群的来合作”“长期能搞站的来合作”,并在 #39 中新增收购 WebShell、境外 gov/edu 站点、根目录权限及服务器权限等合作条件
Associated pattern:结合生效裁判中已经确认的赌博关键词、自动跳转及搜索引擎导流行为,本页面将相关站点、站群合作、境外线路、跳转脚本及SEO导流统一归入博彩 / 引流业务线索进行整理
TRON Wallet and Fund Flows
TZ•••••••••••••••••••••••••••••••••Data period:2026-03-17 至 2026-09-04(UTC)
Fund-flow characteristics:During the observed period, this address continuously received and sent USDT, with frequent activity, multiple upstream sources and multiple downstream distributions The overall pattern is more consistent with an active receiving, settlement or intermediary wallet than a long-term static holding address Only aggregate data are shown and specific addresses and transaction hashes are masked
Passport and National ID Information
| Document Type | Document Number | Valid Until | Status | Issuing Place |
|---|---|---|---|---|
| Ordinary Passport | E74041211 | 2026-05-10 | Inactive | 辽宁省丹东市 |
| Resident Identity Card | 210623199505080956 | Long-term | Valid | Qianyang Town, Donggang, Liaoning, China |
Entry and Exit Records
| No | Exit / Entry | Date | Document | Document Number | Port of Entry / Exit | Flight | Overseas Country / Location (flight-based inference) |
|---|---|---|---|---|---|---|---|
| 1 | Entry | 2017-09-27 | Ordinary Passport | E74041211 | Beijing Capital Airport | D7316 | Malaysia · Kuala Lumpur (KUL) |
| 2 | Exit | 2017-06-19 | Ordinary Passport | E74041211 | Beijing Capital Airport | 5J673 | Philippines · Manila (MNL) |
| 3 | Entry | 2017-03-27 | Ordinary Passport | E74041211 | Shenzhen Airport | AK128 | Malaysia · Kuala Lumpur (KUL) |
| 4 | Exit | 2016-12-29 | Ordinary Passport | E74041211 | Shanghai Pudong Airport | FM861 | Malaysia · Kuala Lumpur (KUL) |
| 5 | Entry | 2016-06-23 | Ordinary Passport | E74041211 | Shanghai Pudong Airport | FM862 | Malaysia · Kuala Lumpur (KUL) |
| 6 | Exit | 2016-05-24 | Ordinary Passport | E74041211 | Shanghai Pudong Airport | FM861 | Malaysia · Kuala Lumpur (KUL) |
Query range:1 January 2007 to 21 August 2026 The electronic file notes that records may contain errors or omissions caused by data collection, transmission or processing
Flight-location note:Public route information maps D7316 to Kuala Lumpur → Beijing, 5J673 to Beijing → Manila, AK128 to Kuala Lumpur → Shenzhen, and FM861/FM862 to Shanghai Pudong ↔ Kuala Lumpur Therefore the added country/location column shows the overseas endpoint of the corresponding flight rather than a field contained in the immigration document
Overall Case and Public Activity Timeline
Court Judgment × Entry/Exit Record Cross-Check Timeline
本时间线将国家移民管理局出入境记录与(2019)苏01刑终768号裁定书中涉及祝东的时间、地点信息并列展示 “航班境外端点”来自公开航线资料推定;法院事实以裁判文书中的认定为准
Entered through Shanghai Pudong Airport on flight FM862 Public route information corresponds to Kuala Lumpur (KUL) → Shanghai Pudong
Exited through Shanghai Pudong Airport on flight FM861, with the overseas endpoint corresponding to Kuala Lumpur, Malaysia (KUL)
Entered through Shenzhen Airport on flight AK128 Public route information corresponds to Kuala Lumpur (KUL) → Shenzhen
Exited through Beijing Capital Airport on flight 5J673 Public route information corresponds to Beijing → Manila, Philippines (MNL) Chinese entry/exit records do not show subsequent flight segments occurring entirely outside China
Criminal Ruling (2019) Su 01 Xing Zhong No 768 found that Zhang Junjie, Peng Linglong, Zhu Dong and Jiang Yuhao acted pursuant to prior agreement at Unit 902, Block B, Trillion Apartments in Kuala Lumpur, Malaysia, illegally controlling vulnerable target servers and uploading static pages containing gambling keywords and automatic redirects
The court-identified “activity in Kuala Lumpur beginning in July 2017” falls entirely within the window between this departure and re-entry: departure from China before July and re-entry on 27 September
Entered through Beijing Capital Airport on flight D7316 Public route information corresponds to Kuala Lumpur, Malaysia (KUL) → Beijing (PEK)
The judgment states that by the end of September 2017, the four defendants had connected to 113 target servers implanted with malware Zhu Dong entered Beijing from the Kuala Lumpur direction on 27 September, closely matching the ending phase of the overseas activity described in the judgment
The judgment states that Zhu Dong was arrested in Zhenxing District, Dandong, Liaoning, roughly two months after the 27 September 2017 entry record and consistent with his having returned to China
Nanjing Intermediate People’s Court issued the final ruling (2019) Su 01 Xing Zhong No 768, dismissing the appeal and affirming the original judgment Zhu Dong was sentenced to three years and six months imprisonment and fined RMB 40,000 for illegally controlling computer information systems
Entry/exit source:National Immigration Administration “Entry and Exit Record Query Result (Electronic File)”, covering 2007-01-01 to 2026-08-21
Court source:Jiangsu Nanjing Intermediate People’s Court Criminal Ruling (2019) Su 01 Xing Zhong No 768 The later “Final Judgment” section also links to Supreme People’s Court Guiding Case No 145
Criminal Conduct Confirmed by Final Judgment
Case:Zhang Junjie, Peng Linglong, Zhu Dong and Jiang Yuhao — Illegal Control of Computer Information Systems
| Detention entry date | ★ 重点2017-11-30 |
|---|---|
| Reason for detention | Criminal detention |
| Case category | ★ 对应非法侵入计算机信息系统案 |
| Year of legal document | 2018年 |
| Detention exit date | ★ 节点2019-10-16 |
| Judicial result | ★ 重点Fixed-term imprisonment |
| Reason for exit | ★ 重点Transferred to prison |
| Identity information | 男,汉族,1995-05-08出生,身高180 cm,足长26 cm,身份栏记载“无业人员” |
| Brief case description | ★ 手法对应记录显示某省政府官网服务器遭攻击并留下后门程序 |
★ Judgment × detention-record cross-analysis
最高人民法院指导案例145号《张竣杰等非法控制计算机信息系统案》记载: 祝东与其他被告人事先共谋,为赚取赌博网站广告费用,检索存在防护漏洞的目标服务器, 植入木马程序取得控制权限,并上传含赌博关键词及自动跳转功能的静态网页, 以提高赌博网站广告被搜索引擎命中的概率
| Final Appellate Case Number | (2019) Su 01 Xing Zhong No 768 |
|---|---|
| Offense Confirmed by Final Judgment | Illegal Control of Computer Information Systems |
| Sentence | Three years and six months imprisonment |
| Fine | RMB 40,000 |
| Disgorged Illegal Proceeds | RMB 25,000 |
| Relevant Legal Provisions | PRC Criminal Law Article 285 paragraphs 1 and 2 |
| Judgment Status | Appeal dismissed, original judgment affirmed, ruling final |
Judicial source: Supreme People’s Court Guiding Case No 145 (approved by the Supreme People’s Court Adjudication Committee and published on 29 December 2020)
Modus Operandi / Operational Analysis
| Stage | Main techniques described in public research | Purpose / Effect | Sources |
|---|---|---|---|
| 1 · Target acquisition at scale | 大规模搜集互联网暴露网站与服务器,优先利用已公开漏洞、配置弱点或可上传 Web Shell 的入口 | 快速扩大可控制服务器数量,并优先利用政府、教育、企业等原本具有较高搜索信誉的域名 | Talos UAT-10147、UAT-8099;Elastic REF4033 |
| 2 · Initial access | 通过远程代码执行、文件上传缺陷、Web Shell 或既有后门获得命令执行与文件修改能力 | 取得对网站目录、IIS 配置和服务器环境的操作权限 | Talos UAT-10147 / UAT-8099;加拿大 SharpViewStateKing |
| 3 · Reconnaissance and environment discovery | 识别 IIS 站点、虚拟目录、权限、运行账号、系统版本及可写路径,并判断后续可植入位置 | 选择最稳定的持久化方式,并发现同一服务器上的更多网站资源 | Talos UAT-10147;加拿大 SharpViewStateKing |
| 4 · Persistence and privilege escalation | 创建额外账号、部署远程控制组件、计划任务、服务或长期 Web Shell,并尝试获得更高系统权限 | 即使原始漏洞被修复,也能继续控制服务器并重复利用其网站资源 | Talos UAT-10147 / SPECTRE / UAT-8099; Elastic REF4033 |
| 5 · Defense evasion | 通过修改安全配置、排除特定目录、混淆组件或采用更低检测率的模块来降低被安全软件发现的概率 | 延长驻留时间,为后续 SEO 欺诈、流量劫持和数据窃取提供稳定环境 | Talos UAT-10147 / SPECTRE; Elastic REF4033; Canadian SharpViewStateKing research |
| 6 · IIS / BadIIS implantation | 把恶意 IIS 模块、ASP.NET 处理器、PHP 脚本或其他流量控制组件嵌入服务器请求链 | 不必修改正常页面主体,也能在服务器层面对进入与返回的 HTTP 流量进行判断、替换或转发 | SOC Prime / Talos BadIIS;Unit 42 Operation Rewrite;Elastic REF4033 |
| 7 · Search-engine deception | 根据 User-Agent、Referer、URL 关键词等条件识别搜索引擎爬虫,为爬虫动态提供大量关键词页、垃圾链接或远端生成的 SEO 内容 | 借用被入侵合法网站的域名信誉,让攻击者指定的关键词更容易进入搜索结果 | Unit 42 Operation Rewrite;Talos UAT-8099;Elastic REF4033 |
| 8 · Cloaking and visitor segmentation | 对搜索爬虫与普通访客返回不同内容:爬虫看到关键词页面,真实用户从搜索结果进入后则被重定向或代理到其他页面 | 隐藏真实用途,同时把自然搜索流量转换成博彩、色情、诈骗或其他付费落地页流量 | Unit 42 Operation Rewrite;Talos UAT-8099;Elastic REF4033 |
| 9 · JavaScript / page-level redirects | 除服务器级 BadIIS 外,也可通过 JavaScript、ASP.NET 或 PHP 等更轻量方式部署跳转逻辑;本页面已收录的 nb.js 与 vnnb.js 即属于直接将访客送往指定域名的脚本形式 | 快速替换推广目标,便于不同品牌、线路或渠道之间切换 | Gurucul IOC;本页面收录的公开 JS 样本;SOC Prime / Talos builder 研究 |
| 10 · Data and server-resource reuse | 部分活动除 SEO 欺诈外还会收集网站源码、配置、凭据、证书或系统信息,并利用同一服务器继续发现更多站点 | 扩大可继续入侵或变现的资产范围,同时为后续权限维持与横向操作提供材料 | Unit 42 Operation Rewrite;Talos UAT-8099 / UAT-10147;加拿大 SharpViewStateKing |
| 11 · Automation and AI assistance | 将漏洞验证、环境侦察、载荷生成、部署检查和故障排查脚本化,Talos 还观察到 AI 工具被用于生成和验证部分入侵工作流 | 降低单个目标所需人工时间,使同一套流程更容易复制到大量服务器 | Talos UAT-10147 / SPECTRE |
| 12 · Site-network cooperation and monetization | 把被控制的网站视作可持续运营的“站群 / 流量资源”,通过即时通讯渠道寻找网站、权限、线路或推广合作,并结合加密资产进行结算 | 将技术入侵、站点控制、流量运营与商业变现拆分为可重复的合作链条 | 本页面 Telegram 存档、TRON 流水与法院既有获利模式记录 |
批量筛选互联网暴露目标 → 利用漏洞或 Web Shell 获得服务器权限 → 枚举 IIS 与网站环境 → 建立长期驻留并提升权限 → 规避安全软件 → 植入 BadIIS / ASP.NET / PHP / JavaScript 流量控制组件 → 针对搜索引擎爬虫投放关键词和 SEO 内容 → 对真实访客实施跳转、反向代理或页面替换 → 将流量导向博彩及其他付费落地页 → 收集源码、配置或凭据并复用更多站点 → 通过自动化和 AI 辅助扩大操作规模 → 以站群合作和加密资产结算完成持续变现
这些公开研究共同体现的核心并不是单一“挂跳转页面”,而是把已经具有信誉和搜索权重的正常网站变成可长期控制的流量基础设施:前端表现为 SEO 关键词、搜索结果污染和跳转,后端则包含权限维持、IIS 模块植入、服务器资源复用、数据收集和批量自动化
| Monetization stage | Method | Revenue source / commercial value | Basis on this page |
|---|---|---|---|
| 1 · Gambling advertising fees | 控制服务器后植入赌博关键词、自动跳转页面,提高赌博广告在搜索引擎中的命中率 | 按广告展示、点击、导流或合作约定获取费用 | 生效裁判已明确记载“为赚取赌博网站广告费用” |
| 2 · SEO traffic monetization | 利用正常网站已有的域名信誉与搜索权重生成关键词页、垃圾链接或动态 SEO 内容,再将真实访客送往指定落地页 | 把原本属于正常网站的搜索流量转换为可出售、可分成或可计费的推广流量 | Talos、Elastic、Unit 42 等公开研究 |
| 3 · Gambling / scam landing-page traffic diversion | 通过 BadIIS、反向代理、JavaScript、ASP.NET 或 PHP 跳转,将访客导向博彩、诈骗或其他商业落地页 | 按流量、注册、充值、转化或渠道合作模式产生收益 | 公开安全研究;页面收录的 nb.js、vnnb.js 跳转样本 |
| 4 · Site-network / access-resource cooperation | 将已控制网站、站群、服务器权限和境外线路作为可重复使用的资源,与其他推广方或技术方合作 | 通过出租、合作分成、代投放或按站点/线路收费实现变现 | 页面收录的 Telegram 频道公开存档 |
| 5 · Server-resource reuse | 在同一服务器继续枚举更多站点、复用源码、配置、凭据或现有权限,将一次入侵扩展为多个可运营资产 | 降低新增站点的获取成本,提高单台服务器的持续产出价值 | Talos、Unit 42、加拿大网络安全中心等公开研究 |
| 6 · Automation at scale | 把目标发现、漏洞验证、部署、跳转规则和故障排查脚本化,并利用自动化或 AI 辅助扩大操作数量 | 降低人工成本,使同类流量资产能够批量复制和持续运营 | Talos UAT-10147 等公开研究 |
| 7 · Fund settlement | 合作收益通过传统账户或加密资产进行接收、转移和分流;页面收录的 TRON 地址表现为持续 USDT 收付 | 用于跨境、快速或多方合作结算 | 裁判中的账户接收 / 转移赃款记录;页面 TRON / USDT 汇总 |
拿到网站或服务器权限 → 借用域名权重做 SEO → 从搜索引擎获取自然流量 → 根据访客来源实施 Cloaking / 跳转 → 导向博彩或其他付费页面 → 按广告、流量、注册、充值或合作分成获利 → 继续复用站群与服务器资源 → 通过账户或 USDT 等方式完成结算
Research basis:本节技术画像依据页面“公开安全研究与关联说明”中列出的 Cisco Talos、Elastic Security Labs、Palo Alto Networks Unit 42、加拿大网络安全中心、SOC Prime 与 Gurucul 公开研究进行归纳;其中各研究描述的是对应威胁活动或恶意软件生态,本节用于总结技术模式,不把不同研究中的活动主体自动视为同一行为人
Public Security Research and Related Analysis
下列安全机构公开报告记录了近年来针对 IIS 服务器的大规模入侵、BadIIS 恶意模块部署、搜索引擎优化(SEO)投毒及向赌博、色情或加密货币诈骗网站 重定向流量等活动这些技术与最高人民法院指导案例145号所记载的服务器控制、 赌博关键词植入及自动跳转行为存在模式上的相似之处
| Publisher | Research Topic | Key Findings | Source |
|---|---|---|---|
| SOC Prime / Cisco Talos | BadIIS Commodity Malware Ecosystem | The report states that multiple Chinese-speaking cybercrime operators use BadIIS against IIS servers for SEO manipulation, malicious traffic redirects, reverse proxying and outbound-link injection, with related activity continuing from at least 2021 into early 2026 | View Report |
| Cisco Talos | From PDB strings to MaaS: Commodity BadIIS ecosystem | Talos reported on May 19, 2026 that a demo.pdb-identified BadIIS variant and its builder were likely sold or shared as commodity malware among multiple Chinese-speaking cybercrime groups The builder can generate configuration files, JavaScript redirectors and PHP backlink scripts, and supports traffic redirection, reverse proxying, content hijacking, and internal / external link injection for SEO fraud |
View Talos Article |
| Elastic Security Labs | REF4033 Global SEO Poisoning Campaign | The report states that more than 1,800 Windows servers were affected across government, education and enterprise victims Compromised servers were used to redirect traffic to gambling sites and cryptocurrency scam pages, and the activity was assessed as consistent with UAT-8099 | View Report |
| Palo Alto Networks Unit 42 | Operation Rewrite / CL-UNK-1037 | Researchers assessed with high confidence, based on language, infrastructure and code characteristics, that the activity was operated by Chinese speakers, and identified infrastructure and architectural overlap with Group 9 The report also noted only limited similarities with DragonRank | View Report |
| Canadian Centre for Cyber Security | SharpViewStateKing Implant Framework | The report analyzes an incident involving SharpViewStateKing, Godzilla and BadIIS, covering web-server control, privilege escalation, remote execution, credential theft and lateral movement | View Report |
| Gurucul | UAT-10147 / SPECTRE threat research | Gurucul's August 24, 2026 research describes UAT-10147 as a Chinese-speaking intrusion operation targeting IIS and Linux servers Its IOC list directly includes https://js.jyzyps.com/js/vnnb.js and https://js.jyzyps.com/js/nb.js, together with additional domains, IP addresses and file hashes associated with the activity |
View Report |
| RedQueen / TJ-UN | Threat-intelligence detail entry | Included as an additional cross-reference for the security-research materials collected on this page | View Intelligence Entry |
| Cisco Talos | UAT-10147 / SPECTRE cross-platform implant | Talos reported on August 20, 2026 that SPECTRE is a cross-platform backdoor with a Linux kernel-level Specter rootkit The research documents Windows and Linux persistence, process injection, credential theft, anti-analysis and defense-evasion capabilities, including Windows BYOVD-based EDR bypass and Linux rootkit hiding / privilege escalation The same research also describes BadIIS and an ASHX SEO engine used for search-engine manipulation and malicious JavaScript delivery | View Talos Article |
| Cisco Talos | UAT-10147: Agentic AI in post-compromise operations | Talos reported on August 20, 2026 that UAT-10147 targeted Windows and Linux web servers globally using publicly disclosed vulnerabilities, automated reconnaissance, payload generation and persistence workflows The report also documents deployment of BadIIS and SPECTRE components, SEO fraud and data theft | View Report |
| Cisco Talos | UAT-8099 Chinese-Speaking Cybercrime Group | Talos identified and began tracking UAT-8099 in April 2025 The group targeted high-value IIS servers in India, Thailand, Vietnam, Canada and Brazil, using Web Shells, RDP, Cobalt Strike and multiple BadIIS samples to maintain control and conduct SEO fraud, while stealing credentials, configuration files and certificate data Compromised servers also redirected users to unauthorized advertising or illegal gambling sites | View Report |