Unearthing DNS Facts about UAT-8099

Several cyber attacks attributed to the Cisco Talos-tracked UAT-8099 campaign have targeted vulnerable Microsoft IIS servers across Asia since late 2025. The activity leveraged web shells, PowerShell scripts, and the GotoHTTP tool to gain remote access, alongside region-specific BadIIS variants.

Cisco Talos identified1 17 network IoCs. After refining the dataset using the WhoisXML API MCP Server, we analyzed 27 IoCs comprising 10 domains and 17 subdomains. Using our tools to expand the investigation, we uncovered these findings:

  • Two unique client IP addresses communicated with two domains tagged as IoCs
  • Three domains named as IoCs were deemed likely to turn malicious 545–569 days prior to being dubbed as such
  • 12,787 email-connected domains, four of which were classified as malicious
  • 13 IP addresses, 12 of which were categorized as malicious
  • 76 string-connected domains

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://github.com/Cisco-Talos/IOCs/blob/main/2026/01/uat-8099-new-persistence-mechanisms-and-regional-focus.txt
Try our WhoisXML API for free
Get started