BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by Chinese-Speaking Cybercrime Groups (2021-2026) — Threadlinqs Intelligence
As of 2026-05-30, BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by Chinese-Speaking Cybercrime Groups (2021-2026) is a high-severity malware threat attributed to lwxat (China (developer and operator language assessment)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 53 indicators of compromise.
Threat ID: TL-2026-0532 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: lwxat · China (developer and operator language assessment) · FINANCIAL
Cisco Talos uncovered a sustained BadIIS commodity malware-as-a-service ecosystem identifiable by embedded 'demo.pdb' strings, developed by an author operating under the alias 'lwxat' from at least
Cisco Talos published research on May 19, 2026 documenting a sustained, commodity malware-as-a-service (MaaS) ecosystem built around a BadIIS variant uniquely identifiable by embedded PDB strings of the form 'demo.pdb' compiled from Desktop folders such as 'C:\Users\Administrator\Desktop\<date-or-feature>\Release\demo.pdb'. The development effort spans at least September 30, 2021 (earliest PDB) through January 6, 2026 (latest PDB observed), and shows clear feature branching — including Baidu compatibility, robots.txt hijacking, TCP enhancements, Norton AV bypass (PDB folder '2024-05-05-tcp(过诺顿)xshen'), and custom site hijacking with browser-language-based redirection (PDB '2025-11-21 (x神订制全站劫持按浏览器语言跳转)').
The ecosystem is attributed to a single developer alias 'lwxat'. Evidence of attribution converges on (1) the builder authentication mechanism, which checks for the response string 'lwxat' from a designated authentication URL before allowing build operations; (2) the configuration parameter 'lwxat' used as an enable function in builder-generated config.txt files; (3) the custom HTTP User-Agent 'lwxatisme' used by BadIIS modules during C2 communication; and (4) dedicated PDB folders for customer 'x神' (xshen) customizations.
BadIIS is implemented as a native IIS module DLL injected into the w3wp.exe request/response pipeline through registration in IIS configuration under <globalModules> and <modules>. Four primary post-compromise functions are exposed: (a) Traffic Redirection — JavaScript-based redirectors are injected into victim HTTP responses to forcibly send legitimate user traffic to spam infrastructure (illegal gambling, adult content); (b) Reverse Proxy / Crawler Interception — the module identifies search-engine crawler requests (notably Baidu's spider) and reverse-proxies illicit content from C2 exclusively to crawlers, while serving normal content to ordinary users; (c) Content Hijacking — the module replaces page title, description, and keyword (TDK) metadata, with configurable hijacking rate, fetching malicious TDK content dynamically from remote URLs; and (d) Backlink Injection — automatically discovers internal links and injects external backlinks to siphon Domain Authority into illicit destination sites.
C2 communication uses single-byte XOR encoding with key 0x3 for C2 address strings embedded in binaries, double Base64 obfuscation for server addresses in the earlier installer variants, and a custom Base64 variant for command parameters in newer auxiliary tools. The builder, dated August 22, 2022 (advertised as version 1.0 with original 2021 release), stages unconfigured 32-bit and 64-bit BadIIS binary templates and bakes operator-supplied parameters from a config.txt directly into the output binaries.
Four distinct generations of auxiliary tooling were observed. The earliest installer registers a Windows service named 'Winlogin' and uses two-stage C2 (primary for 'lwxat' authentication, secondary for payload download). A configuration-driven service installer reads an external XML-like config.txt and dynamically assembles deployment command lines. A unified authentication & configuration tool consolidates these capabilities with custom Base64 obfuscation. The latest generation splits primary and secondary installers — the primary handles C2 authentication, BadIIS discovery, payload copying, and IIS module registration, while the secondary masquerades as legitimate Windows services 'FaxService' or 'AudiosService' and maintains a hidden backup directory copy that restores BadIIS DLLs after IIS restarts. A module-initialization dropper packages 32-bit/64-bit BadIIS payloads as resources 'IIS32' and 'IIS64' in a standalone executable (PDB: 'D:\vc\dll封装进exe\x64\Release\moduleinit.pdb').
Talos assesses with moderate confidence that multiple independent Chinese-speaking cybercrime groups consume the lwxat toolset, similar to but distinct from prior tracked actors DragonRank and UAT-8099. Observed victimology spa
Weaknesses (CWE)
CWE-829, CWE-506, CWE-94
Target sectors: web-hosting, government, education, financial, media-publishing, e-commerce, small-business
Target regions: Asia-Pacific, East Asia, Southeast Asia, South Africa, Europe, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 53 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1190, T1059, T1059.003, T1569.002, T1505.004, T1543.003, T1574.001, T1036.005, T1036.003, T1140