Threat reportMalwareTL-2026-0532

BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by Chinese-Speaking Cybercrime Groups (2021-2026)

highACTIVE

BadIIS 'demo.pdb' Commodity MaaS Ecosystem (TL-2026-0532), also tracked as demo.pdb BadIIS, is a high-severity malware campaign, first published 2026-05-19. It is linked to a China-nexus actor with medium confidence, affects Microsoft Internet Information Services (IIS), maps to 24 MITRE ATT&CK techniques (T1001, T1007, T1027), and is covered by 9 detection rules and 53 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
53Indicators of compromise

Key facts for TL-2026-0532

Threat ID
TL-2026-0532
Also known as
demo.pdb BadIIS, lwxat BadIIS, BadIIS MaaS ecosystem
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
web-hosting, government, education, financial, media-publishing, e-commerce, small-business
Target regions
Asia-Pacific, East Asia, Southeast Asia, South Africa, Europe, North America
Detection rules
9
Indicators of compromise
53

Malware and tooling in BadIIS 'demo.pdb' Commodity MaaS Ecosystem

Malware and tooling: IISpy, Win.Malware.BadIIS (Cisco ClamAV family signatures 10059971-0, 10059977-0, 10059984-0, 10059985-0), lwxat BadIIS builder v1.0, lwxat module-initialization dropper (moduleinit.exe)

How BadIIS 'demo.pdb' Commodity MaaS Ecosystem works

Cisco Talos uncovered a sustained BadIIS commodity malware-as-a-service ecosystem identifiable by embedded 'demo.pdb' strings, developed by an author operating under the alias 'lwxat' from at least September 2021 through January 2026. The author maintains a dedicated builder, multiple auxiliary installer/dropper generations, and reactive evasion against Norton AV — and ships the toolchain to multiple Chinese-speaking cybercrime groups who deploy it against IIS web servers in Asia-Pacific, South Africa, Europe, and North America for SEO fraud (Baidu manipulation), traffic redirection to illegal gambling/adult sites, content hijacking, and backlink siphoning.

Cisco Talos published research on May 19, 2026 documenting a sustained, commodity malware-as-a-service (MaaS) ecosystem built around a BadIIS variant uniquely identifiable by embedded PDB strings of the form 'demo.pdb' compiled from Desktop folders such as 'C:\Users\Administrator\Desktop\<date-or-feature>\Release\demo.pdb'. The development effort spans at least September 30, 2021 (earliest PDB) through January 6, 2026 (latest PDB observed), and shows clear feature branching — including Baidu compatibility, robots.txt hijacking, TCP enhancements, Norton AV bypass (PDB folder '2024-05-05-tcp(过诺顿)xshen'), and custom site hijacking with browser-language-based redirection (PDB '2025-11-21 (x神订制全站劫持按浏览器语言跳转)').

The ecosystem is attributed to a single developer alias 'lwxat'. Evidence of attribution converges on (1) the builder authentication mechanism, which checks for the response string 'lwxat' from a designated authentication URL before allowing build operations; (2) the configuration parameter 'lwxat' used as an enable function in builder-generated config.txt files; (3) the custom HTTP User-Agent 'lwxatisme' used by BadIIS modules during C2 communication; and (4) dedicated PDB folders for customer 'x神' (xshen) customizations.

BadIIS is implemented as a native IIS module DLL injected into the w3wp.exe request/response pipeline through registration in IIS configuration under <globalModules> and <modules>. Four primary post-compromise functions are exposed: (a) Traffic Redirection — JavaScript-based redirectors are injected into victim HTTP responses to forcibly send legitimate user traffic to spam infrastructure (illegal gambling, adult content); (b) Reverse Proxy / Crawler Interception — the module identifies search-engine crawler requests (notably Baidu's spider) and reverse-proxies illicit content from C2 exclusively to crawlers, while serving normal content to ordinary users; (c) Content Hijacking — the module replaces page title, description, and keyword (TDK) metadata, with configurable hijacking rate, fetching malicious TDK content dynamically from remote URLs; and (d) Backlink Injection — automatically discovers internal links and injects external backlinks to siphon Domain Authority into illicit destination sites.

C2 communication uses single-byte XOR encoding with key 0x3 for C2 address strings embedded in binaries, double Base64 obfuscation for server addresses in the earlier installer variants, and a custom Base64 variant for command parameters in newer auxiliary tools. The builder, dated August 22, 2022 (advertised as version 1.0 with original 2021 release), stages unconfigured 32-bit and 64-bit BadIIS binary templates and bakes operator-supplied parameters from a config.txt directly into the output binaries.

Four distinct generations of auxiliary tooling were observed. The earliest installer registers a Windows service named 'Winlogin' and uses two-stage C2 (primary for 'lwxat' authentication, secondary for payload download). A configuration-driven service installer reads an external XML-like config.txt and dynamically assembles deployment command lines. A unified authentication & configuration tool consolidates these capabilities with custom Base64 obfuscation. The latest generation splits primary and secondary installers — the primary handles C2 authentication, BadIIS discovery, payload copying, and IIS module registration, while the secondary masquerades as legitimate Windows services 'FaxService' or 'AudiosService' and maintains a hidden backup directory copy that restores BadIIS DLLs after IIS restarts. A module-initialization dropper packages 32-bit/64-bit BadIIS payloads as resources 'IIS32' and 'IIS64' in a standalone executable (PDB: 'D:\vc\dll封装进exe\x64\Release\moduleinit.pdb').

Talos assesses with moderate confidence that multiple independent Chinese-speaking cybercrime groups consume the lwxat toolset, similar to but distinct from prior tracked actors DragonRank and UAT-8099. Observed victimology spans Asia-Pacific (primary), South Africa, Europe, and North America. The campaign targets opportunistic IIS web server compromise rather than a specific vertical. Detection coverage is shipped by Talos as ClamAV signatures (Win.Malware.BadIIS-10059971-0, -10059977-0, -10059984-0, -10059985-0) and Snort rules (Snort 2: 1:66400, 1:66399, 1:66398; Snort 3: 1:66400, 1:301491).

MITRE ATT&CK techniques used in TL-2026-0532

Command and Control

T1001 Data Obfuscation; T1071.001 Application Layer Protocol: Web Protocols; T1090.001 Proxy: Internal Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding

Discovery

T1007 System Service Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1564.001 Hide Artifacts: Hidden Files and Directories

Execution

T1059 Command and Scripting Interpreter; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1569.002 System Services: Service Execution

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1491.002 Defacement: External Defacement; T1496 Resource Hijacking

Persistence

T1505.004 Server Software Component: IIS Components; T1543.003 Create or Modify System Process: Windows Service

stealth

T1574.001 DLL

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in BadIIS 'demo.pdb' Commodity MaaS Ecosystem

  • Microsoft — Internet Information Services (IIS)
    Vulnerable versions: 7.0; 7.5; 8.0; 8.5; 10.0
  • Microsoft — Windows Server
    Vulnerable versions: 2008 R2; 2012; 2012 R2; 2016; 2019; 2022; 2025

Remediation for BadIIS 'demo.pdb' Commodity MaaS Ecosystem

Patches

  • Apply current Microsoft IIS cumulative updates and Windows security updates to remove initial-access vectors actors use to land BadIIS
  • Update all server-side AV/EDR to latest definitions including Cisco ClamAV signatures Win.Malware.BadIIS-10059971-0/-10059977-0/-10059984-0/-10059985-0
  • Update Snort to deploy rules SIDs 1:66400, 1:66399, 1:66398 (Snort 2) and 1:66400, 1:301491 (Snort 3)

Immediate actions

  • Hunt for IIS modules registered outside of standard Microsoft paths; review <globalModules> and <modules> entries in applicationHost.config for unknown DLLs
  • Block the listed C2 IPs (143.92.36.109, 38.181.52.147, 154.23.186.99, 154.36.149.4, 45.194.17.133) and domains (lee.6686ty.vip, iis.01nmwe.xyz) at perimeter and DNS
  • Alert on outbound HTTP requests carrying User-Agent 'lwxatisme' or fetching '/authorize.txt', '/listen/authorize.txt', or '/pipen/listen.php'
  • Scan w3wp.exe loaded modules and on-disk IIS DLLs for the listed SHA256 hashes
  • Inspect IIS responses for unexpected JavaScript redirectors and TDK (title/description/keywords) metadata replacement

Workarounds

  • Where IIS is not strictly required, disable IIS and remove the Web-Server role
  • Set IIS module list to a known-good allowlist and restart w3wp.exe to drop unauthorized in-memory modules
  • Block known SEO-fraud destination categories (gambling, adult) at egress to reduce monetization value to attackers

Longer-term hardening

  • Enforce least-privilege on IIS service accounts and restrict write access to inetpub, IIS module directories, and applicationHost.config
  • Deploy EDR with behavioral coverage for unsigned/unknown IIS module loads and w3wp.exe child-process spawns
  • Centralize IIS configuration change auditing via Windows event log forwarding (events 5417, 5418) and File Integrity Monitoring on applicationHost.config
  • Subscribe to Cisco Talos and CISA feeds for new lwxat-family IOCs and Snort/ClamAV signature updates
  • Adopt a baseline of expected globalModules entries and alert on deviations

Weaknesses (CWE) in BadIIS 'demo.pdb' Commodity MaaS Ecosystem

CWE-829, CWE-506, CWE-94

Timeline of BadIIS 'demo.pdb' Commodity MaaS Ecosystem

  • Earliest known lwxat compilation observed (PDB path C:\Users\Administrator\Desktop\2021-09-30\x64\Release\demo.pdb) — origin of the demo.pdb BadIIS lineage
  • Early sprint-style build with PDB folder 'dll0217' indicating ongoing reactive development
  • Dedicated lwxat BadIIS builder tool compiled (version 1.0); generates config.txt and bakes operator parameters into 32-bit/64-bit binaries
  • Baidu-browser compatibility and robots.txt hijack branch developed ('兼容百度浏览器+劫持robots.txt')
  • TCP enhancement and Norton AV bypass branch compiled for customer xshen (PDB folder '2024-05-05-tcp(过诺顿)xshen')
  • Custom whole-site hijacking with browser-language-based redirection developed for xshen (PDB '2025-11-21 (x神订制全站劫持按浏览器语言跳转)')
  • Latest observed PDB build (folder 'dll20260106'), confirming continued active development
  • Threadlinqs Intelligence publishes TL-2026-0532 with full MITRE mapping, IOCs, and detection rules
  • Cisco Talos publishes 'From PDB strings to MaaS' research, releases ClamAV/Snort signatures and IOC repository entry commodity_badiis
  • As of 2026-05-29, this remains ACTIVE: Cisco Talos states the lwxat BadIIS MaaS toolset is actively maintained and deployed in the wild, with the latest build dated Jan 6 2026 and no takedown, arrest, or sinkhole reported. As commodity malware sold to multiple Chinese-speaking groups (no CVE, opportunistic IIS compromise), it has no single point of failure and parallel campaigns persist.

Sources cited for BadIIS 'demo.pdb' Commodity MaaS Ecosystem

Detection coverage for TL-2026-0532

As of 2026-05-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0532 across Splunk SPL, Microsoft KQL and Sigma, covering 53 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
53 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats