BadIIS is not acting like a single implant. Talos recovered a builder, which means operators can generate different builds for traffic redirection, crawler manipulation, content hijacking, and SEO fraud. A hunt for one hash or one variant will miss a family that can keep changing form.
Talos tied the malware line to the alias "lwxat" and found evidence of sustained development from at least September 2021 through January 2026. The same research points to rapid feature branching, vendor-specific evasion, and auxiliary tooling for deployment and persistence. That makes BadIIS look like a MaaS ecosystem built for repeated IIS abuse, not a one-off webshell-style intrusion.
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
Cisco Talos has uncovered a BadIIS variant — identifiable by its embedded "demo.pdb" strings — that functions as commodity malware, likely sold or shared among multiple Chinese-speaking cyber crime groups operating under a malware-as-a-service (MaaS) model for continuous monetization.