Cisco Talos reported that a BadIIS malware variant identified by embedded demo.pdb strings is being used as a commodity malware-as-a-service offering by multiple Chinese-speaking cybercrime groups. The IIS malware supports traffic redirection, reverse proxying, content hijacking, and backlink injection, enabling operators to monetize compromised web servers through SEO fraud and other web traffic abuse. Talos said the tooling has been under active development from at least September 2021 through January 2026, with customer-specific builds and feature changes that included antivirus evasion such as Norton bypass functionality.
Researchers also recovered a builder and related installer, dropper, and persistence components tied to the string lwxat, which Talos assesses is likely the developer alias behind the ecosystem. The tooling can deploy both 32-bit and 64-bit BadIIS modules, register them within IIS, and restore hidden backup copies after server restarts to maintain persistence. Activity was observed mainly across the Asia-Pacific region, with additional victims in South Africa, Europe, and North America, while Talos said the shared tooling strongly links the campaigns to the same developer even though attribution to a single threat actor remains difficult.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On publication, Talos disclosed its analysis of a BadIIS malware variant marked by embedded "demo.pdb" strings and described the recovered builder that generates customized IIS payloads and configurations. The report concluded with moderate confidence that the malware is a commodity IIS tool used by multiple Chinese-speaking cybercrime groups.
Cisco Talos reported BadIIS campaigns observed primarily in the Asia-Pacific region, with additional cases in South Africa, Europe, and North America. Despite strong links to the same tooling developer, Talos said attribution to a single threat actor remained difficult because multiple Chinese-speaking groups appeared to use the malware.
During the ecosystem's continued development, the malware gained evasion-oriented changes, including functionality intended to bypass Norton protections. These updates were part of the iterative refinement Talos observed across the BadIIS family.
Over the following years, the developer iteratively updated the BadIIS ecosystem with customer-specific builds, installers, droppers, persistence tools, and monetization-focused capabilities such as traffic redirection, reverse proxying, content hijacking, and backlink injection. Talos assessed with moderate confidence that the malware was being used by multiple Chinese-speaking cybercrime groups in a malware-as-a-service model.
Cisco Talos assessed that the BadIIS tooling family showed sustained development beginning at least in September 2021. The malware lineage was linked through embedded "demo.pdb" strings and related tooling associated with a likely developer using the alias "lwxat."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.