CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

BadIIS 'demo.pdb' MaaS backdoor campaign

campaign · campaign:cisco-talos-badiis-demo-pdb-maas-isapi-backdoor-lwxat-dragon

Commodity malware-as-a-service ISAPI backdoor ('demo.pdb' BadIIS) documented by Cisco Talos: 'lwxat' developer alias, builder tool recovered, UAT-8099 / DragonRank link, 1,800+ IIS servers compromised globally.

Coverage
0
first 2026-05-20 → last –
no data
Latest activity
–
no entry about it yet
Peak priority
·
no entry about it yet
Targets
·
no sector or region stated
Sources cited
0
0 hosts

Story timeline

No published entries reference this entity yet.

Entries about BadIIS 'demo.pdb' MaaS backdoor campaign

No published entry is about this entity yet · an entry attaches by registry key, by the entity's name or a public alias in its title or body, or (for CVE entities) by exact CVE id.

explore in graph