Back to Intel

Intel Node

From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat

lowapt2026-05-19T10:00:20+00:00source excerpt
aptmalwaretradecraftdetection

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware, likely sold or shared among multiple Chinese-speaking cyber crime groups operating under a malware-as-a-service (MaaS) model for continuous monetization.

Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo. pdb" strings — that functions as commodity malware. This variant is likely sold or shared among multiple Chinese-speaking cybercrime groups that operate under a  malware-as-a-service (MaaS)  model for continuous monetization.

  Analysis of program database (PDB) file paths reveals a sustained, multi-year development effort by an author operating under the alias “lwxat”, spanning from at least September 2021 through January 2026, with evidence of rapid iterative updates, feature branching, and reactive evasion tactics targeting specific security vendors such as Norton.

Read Original Source