Twill Typhoon Exploits CDN Masquerading and DLL Sideloading to Breach APJ Networks
ID: 827682d2-6b24-561f-b083-89b186b9659a
STIX ID: report--827682d2-6b24-561f-b083-89b186b9659a
Feed Name: securityonline.info
Darktrace documents an active, highly targeted cyber‑espionage campaign in the Asia‑Pacific and Japan region attributed to the Chinese state‑sponsored group 'Twill Typhoon.' The actors employ DLL sideloading of signed legitimate binaries, CDN‑masquerading domains (e.g., icloud-cdn.net), and an in‑memory, modular .NET RAT that periodically checks a version.txt and loads encrypted payloads (checksum.etl → Client.dll) to dynamically update capabilities while evading signature‑based defenses; defenders are urged to apply strict application allowlisting, monitor for unverified DLL loads, and inspect persistent SSL connections to CDN‑lookalike domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
