BadIIS Builder Turns IIS Abuse Into Commodity

BadIIS is not acting like a single implant. Talos recovered a builder, which means operators can generate different builds for traffic redirection, crawler manipulation, content hijacking, and SEO fraud. A hunt for one hash or one variant will miss a family that can keep changing form. Talos tied the malware line to the alias "lwxat" and found evidence of sustained development from at least September 2021 through January 2026. The same research points to rapid feature branching, vendor-specific evasion, and auxiliary tooling for deployment and persistence. That makes BadIIS look like a MaaS ecosystem built for repeated IIS abuse, not a one-off webshell-style intrusion.

Part of the PlainSec briefing for 2026-05-19

Sources