BadIIS 'demo.pdb' MaaS backdoor campaign
campaign · campaign:cisco-talos-badiis-demo-pdb-maas-isapi-backdoor-lwxat-dragon
Commodity malware-as-a-service ISAPI backdoor ('demo.pdb' BadIIS) documented by Cisco Talos: 'lwxat' developer alias, builder tool recovered, UAT-8099 / DragonRank link, 1,800+ IIS servers compromised globally.
Coverage timeline
0
first 2026-05-20 → last –
no data
Peak priority
—
no matching entries
Sources cited
0
0 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet
Story timeline
No published entries reference this entity yet.
Entries about BadIIS 'demo.pdb' MaaS backdoor campaign
No published entry references this entity yet · entries match by registry key, by the entity's name or a public alias appearing in the entry title or body, or (for CVE entities) by exact CVE id.