logo

From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat

ID: 33e106dc-9920-537c-87f5-cd6ec699e9e8

STIX ID: report--33e106dc-9920-537c-87f5-cd6ec699e9e8

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Joey Chen

...
...

Talos describes a sustained, actively maintained BadIIS malware variant (marked by "demo.pdb" PDB paths) used in global SEO-fraud campaigns against IIS web servers; the report details a modular builder, service-based installers and droppers, persistence and evasion techniques, PDB-derived attribution to the developer alias "lwxat" (and a client "xshen"), multi-year development (2021–2026), and includes IOCs and detection signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.