A sophisticated campaign involving a specific variant of BadIIS malware that actively compromises Internet Information Services (IIS) servers globally.
While attacks primarily target the Asia-Pacific region, researchers have also identified victims across North America, Europe, and South Africa.
Characterized by “demo.pdb” strings hidden in its code, this malware is not the work of a single threat actor.
Instead, evidence indicates BadIIS operates as a commercial commodity tool utilized by multiple Chinese-speaking cybercrime syndicates for search engine optimization (SEO) fraud and malicious traffic redirection.
BadIIS Abuses IIS Redirection
By analyzing the malware’s embedded Program Database (PDB) strings, researchers mapped a sustained development timeline stretching from September 2021 through January 2026.
These artifacts act as a digital fingerprint, revealing periods of rapid updates and specific feature branching.
The creator actively modifies the malware to evade detection, troubleshooting issues that might alert server administrators and even creating specific versions designed to bypass antivirus software like Norton.

At its core, the BadIIS ecosystem relies on a dedicated builder tool that allows cybercriminals to configure and generate malicious payloads with four primary functions:
- Traffic redirection forces legitimate website visitors to route toward illicit spam infrastructure, such as illegal gambling or adult websites.
- Reverse proxying manipulates search engine crawlers by silently fetching malicious content from a command-and-control (C2) server and presenting it for indexing.
- Content hijacking dynamically replaces a compromised website’s original content for both everyday users and search engine bots.
- SEO manipulation injects internal links and external backlinks to siphon a compromised server’s domain authority, artificially boosting the search rankings of external malicious sites.

This BadIIS variant represents a significant shift toward a Malware-as-a-Service (MaaS) business model.
The developer sells a baseline version of the malware alongside the builder utility. If a cybercriminal requires advanced features, such as custom site hijacking based on a victim’s browser language, they can request a bespoke payload.

The threat actor then uses the builder to embed these custom configurations directly into the final malware file using single-byte XOR obfuscation.
According to talos intelligence research, the developer created a suite of specialized installation tools. These include service-based installers that impersonate legitimate Windows services like “Winlogin” or “AudioService.”
The latest versions of these installers use a highly evasive, two-stage process. First, they authenticate with a C2 server using custom Base64 encoding.
Next, they copy the BadIIS payload to both primary and hidden backup directories before registering it within the IIS server.
This robust persistence mechanism ensures the malware automatically restores itself even if the server restarts or security software deletes the primary file.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.