Threat reportMalwareTL-2026-0532
BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by Chinese-Speaking Cybercrime Groups (2021-2026)
BadIIS 'demo.pdb' Commodity MaaS Ecosystem (TL-2026-0532), also tracked as demo.pdb BadIIS, is a high-severity malware campaign, first published 2026-05-19. It is linked to a China-nexus actor with medium confidence, affects Microsoft Internet Information Services (IIS), maps to 24 MITRE ATT&CK techniques (T1001, T1007, T1027), and is covered by 9 detection rules and 53 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 53Indicators of compromise
Key facts for TL-2026-0532
- Threat ID
- TL-2026-0532
- Also known as
- demo.pdb BadIIS, lwxat BadIIS, BadIIS MaaS ecosystem
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- web-hosting, government, education, financial, media-publishing, e-commerce, small-business
- Target regions
- Asia-Pacific, East Asia, Southeast Asia, South Africa, Europe, North America
- Detection rules
- 9
- Indicators of compromise
- 53
Malware and tooling in BadIIS 'demo.pdb' Commodity MaaS Ecosystem
Malware and tooling: IISpy, Win.Malware.BadIIS (Cisco ClamAV family signatures 10059971-0, 10059977-0, 10059984-0, 10059985-0), lwxat BadIIS builder v1.0, lwxat module-initialization dropper (moduleinit.exe)
How BadIIS 'demo.pdb' Commodity MaaS Ecosystem works
Cisco Talos uncovered a sustained BadIIS commodity malware-as-a-service ecosystem identifiable by embedded 'demo.pdb' strings, developed by an author operating under the alias 'lwxat' from at least September 2021 through January 2026. The author maintains a dedicated builder, multiple auxiliary installer/dropper generations, and reactive evasion against Norton AV — and ships the toolchain to multiple Chinese-speaking cybercrime groups who deploy it against IIS web servers in Asia-Pacific, South Africa, Europe, and North America for SEO fraud (Baidu manipulation), traffic redirection to illegal gambling/adult sites, content hijacking, and backlink siphoning.
Cisco Talos published research on May 19, 2026 documenting a sustained, commodity malware-as-a-service (MaaS) ecosystem built around a BadIIS variant uniquely identifiable by embedded PDB strings of the form 'demo.pdb' compiled from Desktop folders such as 'C:\Users\Administrator\Desktop\<date-or-feature>\Release\demo.pdb'. The development effort spans at least September 30, 2021 (earliest PDB) through January 6, 2026 (latest PDB observed), and shows clear feature branching — including Baidu compatibility, robots.txt hijacking, TCP enhancements, Norton AV bypass (PDB folder '2024-05-05-tcp(过诺顿)xshen'), and custom site hijacking with browser-language-based redirection (PDB '2025-11-21 (x神订制全站劫持按浏览器语言跳转)').
The ecosystem is attributed to a single developer alias 'lwxat'. Evidence of attribution converges on (1) the builder authentication mechanism, which checks for the response string 'lwxat' from a designated authentication URL before allowing build operations; (2) the configuration parameter 'lwxat' used as an enable function in builder-generated config.txt files; (3) the custom HTTP User-Agent 'lwxatisme' used by BadIIS modules during C2 communication; and (4) dedicated PDB folders for customer 'x神' (xshen) customizations.
BadIIS is implemented as a native IIS module DLL injected into the w3wp.exe request/response pipeline through registration in IIS configuration under <globalModules> and <modules>. Four primary post-compromise functions are exposed: (a) Traffic Redirection — JavaScript-based redirectors are injected into victim HTTP responses to forcibly send legitimate user traffic to spam infrastructure (illegal gambling, adult content); (b) Reverse Proxy / Crawler Interception — the module identifies search-engine crawler requests (notably Baidu's spider) and reverse-proxies illicit content from C2 exclusively to crawlers, while serving normal content to ordinary users; (c) Content Hijacking — the module replaces page title, description, and keyword (TDK) metadata, with configurable hijacking rate, fetching malicious TDK content dynamically from remote URLs; and (d) Backlink Injection — automatically discovers internal links and injects external backlinks to siphon Domain Authority into illicit destination sites.
C2 communication uses single-byte XOR encoding with key 0x3 for C2 address strings embedded in binaries, double Base64 obfuscation for server addresses in the earlier installer variants, and a custom Base64 variant for command parameters in newer auxiliary tools. The builder, dated August 22, 2022 (advertised as version 1.0 with original 2021 release), stages unconfigured 32-bit and 64-bit BadIIS binary templates and bakes operator-supplied parameters from a config.txt directly into the output binaries.
Four distinct generations of auxiliary tooling were observed. The earliest installer registers a Windows service named 'Winlogin' and uses two-stage C2 (primary for 'lwxat' authentication, secondary for payload download). A configuration-driven service installer reads an external XML-like config.txt and dynamically assembles deployment command lines. A unified authentication & configuration tool consolidates these capabilities with custom Base64 obfuscation. The latest generation splits primary and secondary installers — the primary handles C2 authentication, BadIIS discovery, payload copying, and IIS module registration, while the secondary masquerades as legitimate Windows services 'FaxService' or 'AudiosService' and maintains a hidden backup directory copy that restores BadIIS DLLs after IIS restarts. A module-initialization dropper packages 32-bit/64-bit BadIIS payloads as resources 'IIS32' and 'IIS64' in a standalone executable (PDB: 'D:\vc\dll封装进exe\x64\Release\moduleinit.pdb').
Talos assesses with moderate confidence that multiple independent Chinese-speaking cybercrime groups consume the lwxat toolset, similar to but distinct from prior tracked actors DragonRank and UAT-8099. Observed victimology spans Asia-Pacific (primary), South Africa, Europe, and North America. The campaign targets opportunistic IIS web server compromise rather than a specific vertical. Detection coverage is shipped by Talos as ClamAV signatures (Win.Malware.BadIIS-10059971-0, -10059977-0, -10059984-0, -10059985-0) and Snort rules (Snort 2: 1:66400, 1:66399, 1:66398; Snort 3: 1:66400, 1:301491).
MITRE ATT&CK techniques used in TL-2026-0532
Command and Control
T1001 Data Obfuscation; T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding
Discovery
T1007 System Service Discovery; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories
Execution
T1059 Command and Scripting Interpreter; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1569.002 System Services: Service Execution
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1491.002 Defacement: External Defacement; T1496 Resource Hijacking
Persistence
T1505.004 Server Software Component: IIS Components; T1543.003 Create or Modify System Process: Windows Service
stealth
defense-impairment
Affected products and versions in BadIIS 'demo.pdb' Commodity MaaS Ecosystem
Remediation for BadIIS 'demo.pdb' Commodity MaaS Ecosystem
Patches
- Apply current Microsoft IIS cumulative updates and Windows security updates to remove initial-access vectors actors use to land BadIIS
- Update all server-side AV/EDR to latest definitions including Cisco ClamAV signatures Win.Malware.BadIIS-10059971-0/-10059977-0/-10059984-0/-10059985-0
- Update Snort to deploy rules SIDs 1:66400, 1:66399, 1:66398 (Snort 2) and 1:66400, 1:301491 (Snort 3)
Immediate actions
- Hunt for IIS modules registered outside of standard Microsoft paths; review <globalModules> and <modules> entries in applicationHost.config for unknown DLLs
- Block the listed C2 IPs (143.92.36.109, 38.181.52.147, 154.23.186.99, 154.36.149.4, 45.194.17.133) and domains (lee.6686ty.vip, iis.01nmwe.xyz) at perimeter and DNS
- Alert on outbound HTTP requests carrying User-Agent 'lwxatisme' or fetching '/authorize.txt', '/listen/authorize.txt', or '/pipen/listen.php'
- Scan w3wp.exe loaded modules and on-disk IIS DLLs for the listed SHA256 hashes
- Inspect IIS responses for unexpected JavaScript redirectors and TDK (title/description/keywords) metadata replacement
Workarounds
- Where IIS is not strictly required, disable IIS and remove the Web-Server role
- Set IIS module list to a known-good allowlist and restart w3wp.exe to drop unauthorized in-memory modules
- Block known SEO-fraud destination categories (gambling, adult) at egress to reduce monetization value to attackers
Longer-term hardening
- Enforce least-privilege on IIS service accounts and restrict write access to inetpub, IIS module directories, and applicationHost.config
- Deploy EDR with behavioral coverage for unsigned/unknown IIS module loads and w3wp.exe child-process spawns
- Centralize IIS configuration change auditing via Windows event log forwarding (events 5417, 5418) and File Integrity Monitoring on applicationHost.config
- Subscribe to Cisco Talos and CISA feeds for new lwxat-family IOCs and Snort/ClamAV signature updates
- Adopt a baseline of expected globalModules entries and alert on deviations
Weaknesses (CWE) in BadIIS 'demo.pdb' Commodity MaaS Ecosystem
Timeline of BadIIS 'demo.pdb' Commodity MaaS Ecosystem
- Earliest known lwxat compilation observed (PDB path C:\Users\Administrator\Desktop\2021-09-30\x64\Release\demo.pdb) — origin of the demo.pdb BadIIS lineage
- Early sprint-style build with PDB folder 'dll0217' indicating ongoing reactive development
- Dedicated lwxat BadIIS builder tool compiled (version 1.0); generates config.txt and bakes operator parameters into 32-bit/64-bit binaries
- Baidu-browser compatibility and robots.txt hijack branch developed ('兼容百度浏览器+劫持robots.txt')
- TCP enhancement and Norton AV bypass branch compiled for customer xshen (PDB folder '2024-05-05-tcp(过诺顿)xshen')
- Custom whole-site hijacking with browser-language-based redirection developed for xshen (PDB '2025-11-21 (x神订制全站劫持按浏览器语言跳转)')
- Latest observed PDB build (folder 'dll20260106'), confirming continued active development
- Threadlinqs Intelligence publishes TL-2026-0532 with full MITRE mapping, IOCs, and detection rules
- Cisco Talos publishes 'From PDB strings to MaaS' research, releases ClamAV/Snort signatures and IOC repository entry commodity_badiis
- As of 2026-05-29, this remains ACTIVE: Cisco Talos states the lwxat BadIIS MaaS toolset is actively maintained and deployed in the wild, with the latest build dated Jan 6 2026 and no takedown, arrest, or sinkhole reported. As commodity malware sold to multiple Chinese-speaking groups (no CVE, opportunistic IIS compromise), it has no single point of failure and parallel campaigns persist.
Sources cited for BadIIS 'demo.pdb' Commodity MaaS Ecosystem
- From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat (Cisco Talos)
- Cisco Talos IOCs Repository — commodity_badiis.txt
- Cisco Talos IOCs Repository — commodity_badiis.json
- DragonRank: A Chinese-speaking SEO manipulator (Cisco Talos — historical context)
- UAT-8099 BadIIS SEO fraud campaign (prior Threadlinqs threat TL-2026-0007)
- MITRE ATT&CK T1505.004 — Server Software Component: IIS Components
- Snort rule 1:66400 — BadIIS module activity
Detection coverage for TL-2026-0532
As of 2026-05-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0532 across Splunk SPL, Microsoft KQL and Sigma, covering 53 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.