# BadIIS 'demo.pdb' Commodity MaaS Ecosystem — Cisco Talos Tracks 'lwxat' Author Toolchain Used by Chinese-Speaking Cybercrime Groups (2021-2026)

> Cisco Talos uncovered a sustained BadIIS commodity malware-as-a-service ecosystem identifiable by embedded 'demo.pdb' strings, developed by an author operating under the alias 'lwxat' from at least September 2021 through January 2026. The author maintains a dedicated builder, multiple auxiliary installer/dropper generations, and reactive evasion against Norton AV — and ships the toolchain to multiple Chinese-speaking cybercrime groups who deploy it against IIS web servers in Asia-Pacific, South Africa, Europe, and North America for SEO fraud (Baidu manipulation), traffic redirection to illegal gambling/adult sites, content hijacking, and backlink siphoning.

- **Published:** 2026-05-19T12:00:00Z
- **Last reviewed:** 2026-05-19T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0532
- **ID:** TL-2026-0532
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 53 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Cisco Talos published research on May 19, 2026 documenting a sustained, commodity malware-as-a-service (MaaS) ecosystem built around a BadIIS variant uniquely identifiable by embedded PDB strings of the form 'demo.pdb' compiled from Desktop folders such as 'C:\Users\Administrator\Desktop\<date-or-feature>\Release\demo.pdb'. The development effort spans at least September 30, 2021 (earliest PDB) through January 6, 2026 (latest PDB observed), and shows clear feature branching — including Baidu compatibility, robots.txt hijacking, TCP enhancements, Norton AV bypass (PDB folder '2024-05-05-tcp(过诺顿)xshen'), and custom site hijacking with browser-language-based redirection (PDB '2025-11-21 (x神订制全站劫持按浏览器语言跳转)').

The ecosystem is attributed to a single developer alias 'lwxat'. Evidence of attribution converges on (1) the builder authentication mechanism, which checks for the response string 'lwxat' from a designated authentication URL before allowing build operations; (2) the configuration parameter 'lwxat' used as an enable function in builder-generated config.txt files; (3) the custom HTTP User-Agent 'lwxatisme' used by BadIIS modules during C2 communication; and (4) dedicated PDB folders for customer 'x神' (xshen) customizations.

BadIIS is implemented as a native IIS module DLL injected into the w3wp.exe request/response pipeline through registration in IIS configuration under <globalModules> and <modules>. Four primary post-compromise functions are exposed: (a) Traffic Redirection — JavaScript-based redirectors are injected into victim HTTP responses to forcibly send legitimate user traffic to spam infrastructure (illegal gambling, adult content); (b) Reverse Proxy / Crawler Interception — the module identifies search-engine crawler requests (notably Baidu's spider) and reverse-proxies illicit content from C2 exclusively to crawlers, while serving normal content to ordinary users; (c) Content Hijacking — the module replaces page title, description, and keyword (TDK) metadata, with configurable hijacking rate, fetching malicious TDK content dynamically from remote URLs; and (d) Backlink Injection — automatically discovers internal links and injects external backlinks to siphon Domain Authority into illicit destination sites.

C2 communication uses single-byte XOR encoding with key 0x3 for C2 address strings embedded in binaries, double Base64 obfuscation for server addresses in the earlier installer variants, and a custom Base64 variant for command parameters in newer auxiliary tools. The builder, dated August 22, 2022 (advertised as version 1.0 with original 2021 release), stages unconfigured 32-bit and 64-bit BadIIS binary templates and bakes operator-supplied parameters from a config.txt directly into the output binaries.

Four distinct generations of auxiliary tooling were observed. The earliest installer registers a Windows service named 'Winlogin' and uses two-stage C2 (primary for 'lwxat' authentication, secondary for payload download). A configuration-driven service installer reads an external XML-like config.txt and dynamically assembles deployment command lines. A unified authentication & configuration tool consolidates these capabilities with custom Base64 obfuscation. The latest generation splits primary and secondary installers — the primary handles C2 authentication, BadIIS discovery, payload copying, and IIS module registration, while the secondary masquerades as legitimate Windows services 'FaxService' or 'AudiosService' and maintains a hidden backup directory copy that restores BadIIS DLLs after IIS restarts. A module-initialization dropper packages 32-bit/64-bit BadIIS payloads as resources 'IIS32' and 'IIS64' in a standalone executable (PDB: 'D:\vc\dll封装进exe\x64\Release\moduleinit.pdb').

Talos assesses with moderate confidence that multiple independent Chinese-speaking cybercrime groups consume the lwxat toolset, similar to but distinct from prior tracked actors DragonRank and UAT-8099. Observed victimology spans Asia-Pacific (primary), South Africa, Europe, and North America. The campaign targets opportunistic IIS web server compromise rather than a specific vertical. Detection coverage is shipped by Talos as ClamAV signatures (Win.Malware.BadIIS-10059971-0, -10059977-0, -10059984-0, -10059985-0) and Snort rules (Snort 2: 1:66400, 1:66399, 1:66398; Snort 3: 1:66400, 1:301491).

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1569.002 System Services: Service Execution
- T1505.004 Server Software Component: IIS Components
- T1543.003 Create or Modify System Process: Windows Service
- T1574.001 DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1036.003 Rename Legitimate Utilities
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1564.001 Hide Artifacts: Hidden Files and Directories
- T1685 Disable or Modify Tools
- T1082 System Information Discovery
- T1007 System Service Discovery
- T1071.001 Application Layer Protocol: Web Protocols
- T1132.001 Data Encoding: Standard Encoding
- T1001 Data Obfuscation
- T1105 Ingress Tool Transfer
- T1090.001 Proxy: Internal Proxy
- T1102 Web Service
- T1491.002 Defacement: External Defacement
- T1496 Resource Hijacking

## Sources

- [From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat (Cisco Talos)](https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem/)
- [Cisco Talos IOCs Repository — commodity_badiis.txt](https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2026/05/commodity_badiis.txt)
- [Cisco Talos IOCs Repository — commodity_badiis.json](https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2026/05/commodity_badiis.json)
- [DragonRank: A Chinese-speaking SEO manipulator (Cisco Talos — historical context)](https://blog.talosintelligence.com/dragon-rank-seo-poisoning/)
- [UAT-8099 BadIIS SEO fraud campaign (prior Threadlinqs threat TL-2026-0007)](https://intel.threadlinqs.com/threat/TL-2026-0007)
- [MITRE ATT&CK T1505.004 — Server Software Component: IIS Components](https://attack.mitre.org/techniques/T1505/004/)
- [Snort rule 1:66400 — BadIIS module activity](https://www.snort.org/rule_docs/1-66400)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0532
