INTEL_REPORT
Cisco Talos Blog · published 5/19/2026, 10:00:20 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware, likely sold or shared among multiple Chinese-speaking cyber crime groups operating under a malware-as-a-service (MaaS) model for continuous monetization. Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb&…
https://blog.talosintelligence.com/from-pdb-strings-to-maas-tracking-a-commodity-badiis-ecosystem
sha256:c580b103baec33b4210af890324189c513d35076afb3b8d1e747a3a90e09e9d5
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| service.pdb |
| Open → |
| domain | 32.dll | Open → |
| domain | 64.dll | Open → |
| domain | module.txt | Open → |
| domain | win.malware.badiis | Open → |