DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Topics
Follow your own topics →
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat

28 · Blog Talosintelligence · May 19, 2026, 10:22 a.m.
Threat Spotlight Cisco Talos Malware Protection Cisco Talos Antivirus Cisco Talos Web Filtering Cybersecurity malware MAAS threat-intelligence
Summary
This post discusses the discovery of a BadIIS malware variant that uses 'demo.pdb' strings and operates under a malware-as-a-service model, highlighting its use among Chinese-speaking cyber crime groups.
Read full post on blog.talosintelligence.com →
MORE POSTS LIKE THIS
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Blog Talosintelligence · Jul 16, 2026
Threats rat
security: ACR Stealer: Two observed intrusion chains amid increased threat activity
Sujith Quintelier · Jul 17, 2026
ACR Stealer malware
BlackToad Threat Actors Deploy Stealthy Phishing Lures
Securityonline · Jun 2, 2026
Cybercriminals BlackToad
The Good, the Bad and the Ugly in Cybersecurity – Week 17
Sentinelone · Apr 24, 2026
Company Cyber
Investigating three real-world incidents in our cybersecurity evaluations
simonw · Jul 31, 2026
pypi Python
Admitting the Elephantine Void Between Kinetic and Cyber Threats
Flying Penguin Blog · Jul 22, 2026
Energy history
Discover more posts →
AUTHOR
BLOG POST FEATURED ON

Placeholder image
r/hackerworkspace

1 points

Placeholder image
r/blueteamsec

1 points

Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google