logo

China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage

ID: 79af711d-9dd3-51b4-b118-cfed8bddcbc1

STIX ID: report--79af711d-9dd3-51b4-b118-cfed8bddcbc1

Feed Name: HackRead

Threat Score
85/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Deeba Ahmed

...
...

**Executive summary:** Security researchers attributed a wave of espionage intrusions across Japan and the Asia-Pacific to a China-linked actor known as Twill Typhoon, which uses DLL sideloading of legitimate applications (e.g., Sogou Pinyin, dfsvc.exe, vshost.exe) to load modular malware (FDMTP) and maintain long-lived persistence via scheduled tasks and registry entries; observed infrastructure and artifacts include dnscfg.dll, Assist.dll, Persist.WpTask.dll and faux CDN domains like yahoo-cdn.it.com and icloud-cdn.net.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.