# SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor, and XMRig Deployment

> Threat actors exploited a SQL injection flaw in an unvalidated web application input to compromise a technology-sector organization's Microsoft SQL Server, then pivoted to create a rogue admin account, enable RDP, disable Windows Defender, install malicious BadIIS IIS modules, and deploy the XMRig cryptominer via nssm.exe.

- **Published:** 2026-07-13T00:00:00Z
- **Last reviewed:** 2026-07-13T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1269
- **ID:** TL-2026-1269
- **Severity:** HIGH
- **Category:** INTRUSION
- **Status:** ACTIVE
- **Actor:** UAT-8099 (China)
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Huntress DFIR investigators observed a confirmed intrusion beginning with SQL injection against an IIS-hosted web application where user-supplied input was not validated before reaching the backend Microsoft SQL Server. The injection allowed the attacker to reach OS command execution, observed as sqlservr.exe spawning cmd.exe — consistent with abuse of MSSQL command-execution stored procedures (e.g., xp_cmdshell) reachable from an injectable query. Once on the host, the actor ran reconnaissance (tasklist /svc) and exfiltrated the output via an HTTP POST to an out-of-band interaction domain (334thribetlhkyo977gqrcht1k7bvdj2.oastify.com), a Burp Suite Collaborator/OAST-style subdomain typically used for blind SQLi/SSRF confirmation, indicating the intrusion may itself have originated from automated or semi-automated SQLi tooling reuse, or that the actor repurposed an OAST domain for DNS/HTTP beaconing and exfiltration. The actor created a new local administrator account (adminweb2$), enabled Remote Desktop Services/Terminal Services for interactive follow-on access, and disabled Windows Defender to prepare the host for further tooling. For defense evasion the actor used attrib.exe to mark dropped cryptominer files and directories as system, hidden, archive, and read-only, staging them inside a masquerading path under C:\Program Files (x86)\Microsoft\EdgeUpdate\ to blend in with a legitimate Microsoft update service. The actor installed two malicious IIS modules — HttpFastCgiModule.dll and HttpCgiModule.dll — via appcmd.exe, consistent with the BadIIS malware family (tracked publicly by Cisco Talos as used by the China-nexus group UAT-8099/REF4033 for SEO fraud, illicit traffic redirection, reverse-proxying, and content hijacking on compromised IIS servers worldwide). BadIIS integrates into the IIS request pipeline as a native module, conditionally serving keyword-stuffed content to search crawlers while redirecting real visitors to attacker-controlled destinations (gambling, adult content, crypto-phishing) and can also facilitate credential theft — giving the actor a durable, web-server-native backdoor independent of the initial SQLi foothold. For financial impact, the actor downloaded PowerShell scripts (qdcjoke1.2.ps1, c_joke1.2.ps1) and a batch launcher (qd_tjoke.bat) from a Cloudflare R2 public bucket (pub-c4c8e8c336c3429d97195076bf3bb6eb.r2.dev), executed with powershell.exe -NoLogo -NoProfile -NonInteractive -ExecutionPolicy Bypass -WindowStyle Hidden to suppress visible windows and logging prompts. These scripts staged the XMRig Monero cryptominer (delivered as xmr-1.zip) and registered it as a Windows service using nssm.exe (Non-Sucking Service Manager), a legitimate open-source service-wrapper tool abused here to auto-restart the miner process and blend in among normal Windows services. The actor additionally installed a tool referred to as "CnCrypt Protect" alongside the miner, likely intended to hinder analysis/detection of the miner binary or its configuration. No CVE was assigned by the source reporting since the vulnerability is a generic unvalidated-input SQL injection rather than a specific product flaw; no formal CVSS score was published. The concrete, actionable artifacts — the rogue account name, IIS module filenames, staging paths, script names, and the OAST/R2 delivery infrastructure — make this intrusion highly suited to detection-engineering coverage despite the lack of a CVE/CVSS anchor.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1569 System Services
- T1136 Create Account
- T1505 Server Software Component
- T1543 Create or Modify System Process
- T1133 External Remote Services
- T1078 Valid Accounts
- T1685 Disable or Modify Tools
- T1564 Hide Artifacts
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1218 System Binary Proxy Execution
- T1557 Adversary-in-the-Middle
- T1007 System Service Discovery
- T1057 Process Discovery
- T1069 Permission Groups Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1102 Web Service
- T1090 Proxy
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel
- T1496 Resource Hijacking

## Sources

- [Home Field Advantage: How Attackers Reshape Victim Environments](https://www.huntress.com/blog/sql-injection-attacker-persistence)
- [Dissecting UAT-8099: New persistence mechanisms and regional focus](https://blog.talosintelligence.com/uat-8099-new-persistence-mechanisms-and-regional-focus/)
- [UAT-8099: Chinese-speaking cybercrime group targets high-value IIS for SEO fraud](https://blog.talosintelligence.com/uat-8099-chinese-speaking-cybercrime-group-seo-fraud/)
- [BADIIS to the Bone: New Insights to a Global SEO Poisoning Campaign](https://www.elastic.co/security-labs/badiis-to-the-bone-new-insights-to-global-seo-poisoning-campaign)
- [China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware](https://thehackernews.com/2026/01/china-linked-uat-8099-targets-iis.html)
- [BadIIS Malware Hijacks IIS Servers to Redirect Users to Illicit Sites](https://gbhackers.com/badiis-malware-hijacks-iis/)
- [Newly-discovered threat group hijacking IIS servers for SEO fraud, warns Cisco Talos](https://www.csoonline.com/article/4067773/newly-discovered-threat-group-hijacking-iis-servers-for-seo-fraud-warns-cisco-talos.html)
- [Operation Rewrite: Chinese-Speaking Threat Actors Deploy BadIIS in a Wide Scale SEO Poisoning Campaign](https://unit42.paloaltonetworks.com/operation-rewrite-seo-poisoning-campaign/)
- [Non-Sucking Service Manager (nssm) Usage](https://github.com/SecurityAura/DE-TH-Aura/blob/main/100DaysOfKQL/Day%2057%20-%20Non-Sucking%20Service%20Manager%20(nssm)%20Usage.md)
- [Sqlserver, or the Miner in the Basement](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/)
- [Burp Collaborator documentation (oastify.com domain)](https://portswigger.net/burp/documentation/collaborator)
- [Threat Advisory: XMRig Cryptomining By Way Of TeamViewer](https://www.huntress.com/blog/threat-advisory-xmrig-crypto-mining-by-way-of-teamviewer)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1269
