EPISODE · Oct 3, 2025 · 5 MIN
CISOs Lose Sleep as Chinese Hackers Hijack Servers for SEO Fraud and Illegal Gambling
from Cyber Sentinel: Beijing Watch · host Inception Point AI
This is your Cyber Sentinel: Beijing Watch podcast. Hey listeners, Ting here on Cyber Sentinel: Beijing Watch, where China’s cyber maneuvering meets razor-sharp analysis and just a sprinkle of sarcasm. Strap in—these last few days have been a clinic in how high-level hacking and global diplomacy do a messy tango. Let’s start with a campaign that’s making CISOs lose sleep across multiple continents—UAT-8099, the Chinese-speaking cybercrime crew Cisco Talos has been tracking. Since April 2025, these folks have been hijacking Internet Information Services, or IIS servers—think the digital bouncers for a ton of tech firms, universities, and even telecoms from India to Canada. The twist? They’re not breaking in for state secrets. No, these hackers are doing search engine optimization fraud, quietly boosting shady websites for a payday, and using stolen server rep as rocket fuel for illegal gambling and dodgy ads. Imagine walking into a Fortune 500 boardroom and redirecting everyone to an underground casino. That’s the scale. Their weapon of choice—customized *BadIIS* malware, fresh variants specially built to slip past antivirus software. Once they find a vulnerable server, it’s like a bad houseguest: web shells for snooping, guest accounts promoted straight to admin, Remote Desktop Protocol for persistent access, all backstopped by VPN tools like SoftEther and FRP. They even protect turf with defense tools so other hackers can’t muscle in. And if you’re a mobile user on iOS or Android? Sorry, you’re right in the blast radius, with server-placed fake app downloads tailored just for you. If you’re thinking this is amateur hour—guess again. These operations automate everything, from deploying Cobalt Strike beacons masked as legitimate code modules to injecting malicious JavaScript that fools both Googlebots and your grandma, depending on who visits the link. That means not just operational disruption and credential theft, but an entire criminal economy built on the bones of American, Canadian, and global digital infrastructure. Switching gears, let’s talk Shanghai Suochen Information Technology—a company recently swept into the U.S. Bureau of Industry and Security’s 50% Rule net. This move now means any subsidiary, even those hiding in Europe or deeply nested in Chinese ownership webs, gets the same strict export scrutiny as Suochen itself. Why? Their subsidiaries have supplied simulation tech, electronics, and even naval defense systems to the PLA and related military factories. PLA’s Naval Aviation University? Yep, Suochen’s bids landed there. The kicker—entities in the UK and Hungary, technically “clean,” are now entangled by the rule, so U.S. exporters beware: due diligence just got a hardcore upgrade. What about government responses? China doubled down on its internal defenses with a one-hour reporting rule for cybersecurity incidents. Talk about response agility—if only U.S. agencies moved that fast, especially now with a federal shutdown ho This content was created in partnership and with the help of Artificial Intelligence AI.
Embed this episode
NOW PLAYING
CISOs Lose Sleep as Chinese Hackers Hijack Servers for SEO Fraud and Illegal Gambling
No transcript for this episode yet
Similar Episodes
No similar episodes found.