#
DIFF.BLOG
New
Following
Discover
Jobs
More
Top Writers
Suggest a blog
Upvotes plugin
Report bug
Contact
About
Privacy
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
·
Blog Talosintelligence
·
May 19, 2026, 10:22 a.m.
Threat Spotlight
Cisco Talos Malware Protection
Cisco Talos Antivirus
Cisco Talos Web Filtering
Cybersecurity
MAAS
malware
threat-intelligence
Summary
This post discusses the discovery of a BadIIS malware variant that uses 'demo.pdb' strings and operates under a malware-as-a-service model, highlighting its use among Chinese-speaking cyber crime groups.
Read full post on blog.talosintelligence.com →
MORE POSTS LIKE THIS
Cisco Talos finds malware that puts its next move to a four-model vote
Siliconangle ·
Sep 23, 2026
News
Security
security: Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Sujith Quintelier ·
Sep 3, 2026
Cybersecurity
microsoft teams
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Blog Talosintelligence ·
Jul 16, 2026
Threats
rat
BlackToad Threat Actors Deploy Stealthy Phishing Lures
Securityonline ·
Jun 2, 2026
Cybercriminals
BlackToad
The Good, the Bad and the Ugly in Cybersecurity – Week 17
Sentinelone ·
Apr 24, 2026
Company
Cyber
Malicious npm Packages That Evade Defenses
Bruce Schneier ·
Sep 24, 2026
Defense
malware
Discover more posts →
AUTHOR
Advertise
Sponsor diff.blog
Put your product in front of developers who read and write about their craft. One exclusive sponsor at a time.
Become a sponsor →
BLOG POST FEATURED ON
r/hackerworkspace
1 points
r/blueteamsec
1 points
Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub
Continue with Google
By continuing, you agree to our
Privacy Policy
.