From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
This report details the discovery of a commodity BadIIS malware variant, identified by its "demo.pdb" strings, being utilized by multiple Chinese-speaking cybercrime groups operating under a MaaS model. Developed by an author known as "lwxat" from at least 2021 to 2026, the malware includes builder tools and auxiliary utilities for SEO fraud, content hijacking, and evasion tactics. Investigations, driven by analysis of PDB strings, have revealed a sustained development effort, specific customizations targeting vendors like Norton, and a timeline of updates, highlighting its ongoing deployment in the wild across various regions.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
