#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
·
Blog Talosintelligence
·
May 19, 2026, 10:22 a.m.
Threat Spotlight
Cisco Talos Web Filtering
Cisco Talos Antivirus
Cisco Talos Malware Protection
Cybersecurity
malware
MAAS
threat-intelligence
Summary
This post discusses the discovery of a BadIIS malware variant that uses 'demo.pdb' strings and operates under a malware-as-a-service model, highlighting its use among Chinese-speaking cyber crime groups.
Read full post on blog.talosintelligence.com →
MORE POSTS LIKE THIS
security: Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Sujith Quintelier ·
Sep 3, 2026
Cybersecurity
IT security
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Blog Talosintelligence ·
Jul 16, 2026
Threats
rat
BlackToad Threat Actors Deploy Stealthy Phishing Lures
Securityonline ·
Jun 2, 2026
Cybercriminals
BlackToad
The Good, the Bad and the Ugly in Cybersecurity – Week 17
Sentinelone ·
Apr 24, 2026
Company
Weekly
I'm Worried About a Prompt Injection Worm
Daniel Miessler ·
Aug 19, 2026
AI Security
prompt injection
Investigating three real-world incidents in our cybersecurity evaluations
simonw ·
Jul 31, 2026
Python
AI
Discover more posts →
AUTHOR
Sponsored
Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →
BLOG POST FEATURED ON
r/hackerworkspace
1 points
r/blueteamsec
1 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google