Trusted Windows Paths Carry Twill Typhoon Payloads

Twill Typhoon is getting past hash-based detection by making its intrusion look like normal software delivery. The chain uses CDN impersonation, staged retrieval of legitimate files, and DLL sideloading inside trusted Windows processes, so a playbook built around obvious malware binaries will miss the compromise path. Darktrace says the campaign is hitting organizations in APAC and Japan and is linked with moderate confidence to Twill Typhoon. The activity uses ClickOnce and Visual Studio hosting processes, then runs an updated FDMTP .NET RAT and backdoor with persistence, plugin loading, encrypted command-and-control, and command execution. The risk is prolonged, low-noise access that blends into ordinary Windows and .NET activity. The broader pattern is that the actor is relying on modular, rotating tradecraft rather than fixed indicators, so the behavior of trusted tooling is the signal that matters.

Part of the PlainSec briefing for 2026-05-16

Sources