news.mlab.sh
Back to the feed
malware

From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat

Medium
Image: Cisco Talos
Summary

This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an author known as "lwxat" from at least 2021 to 2026, the malware includes builder tools and auxiliary utilities for SEO fraud, content hijacking, and evasion tactics. Investigations, driven by analysis of PDB strings, have revealed a sustained development effort, specific customizations targeting vendors like Norton, and a timeline of updates, highlighting its ongoing deployment in the wild across various regions.

Read the full article at Cisco Talos

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.