Twill Typhoon — Updated FDMTP Backdoor

Chinese APT espionage campaign: DLL side-loading of legitimate binaries (Sogou Pinyin, Visual Studio, ClickOnce) to launch a modular .NET RAT (FDMTP) over CDN-impersonating C2. Aliases: Earth Preta · Stately Taurus · Bronze President · Mustang Panda · TA416. APAC/Japan, late Sep 2025–Apr 2026.
Threat
Twill Typhoon / FDMTP
Severity
NATION-STATE · ACTIVE
Type
APT espionage · DLL side-loading · .NET RAT
Access
Spear-phish → staged HTTP retrieval
Version
v0.2 · 2026-06-21
Author
HuntPack
Confidence
Moderate (Darktrace-attributed)
01

Executive Summary

Twill Typhoon (Mustang Panda / Earth Preta / Stately Taurus) is running an espionage campaign against APAC and Japanese entities — including finance-sector organizations — from late September 2025 through April 2026, deploying an updated build of the FDMTP modular .NET RAT (observed v3.2.5.1). The actor's objective is durable, low-noise remote access and intelligence collection from trusted-process context.

The core, durable behavior is DLL side-loading: the actor retrieves a legitimate, signed Windows executable, a matching .config file, and a malicious DLL from infrastructure masquerading as Yahoo- and Apple-affiliated CDNs, then lets the trusted binary load the rogue DLL. Confirmed abused binaries: biz_render.exe (Sogou Pinyin IME), vshost.exe (Visual Studio Hosting Process), and dfsvc.exe (.NET ClickOnce engine). The DLL pulls a .NET runtime in-process and stages the FDMTP framework, which communicates over a custom Duplex Message Transport Protocol (DMTP) with a /GetCluster registration URI and a Verify_Token: Dmtp header.

The highest-value defensive angle is behavioral, not indicator-based: the ordered sequence — signed EXE + .config + unsigned/unusual DLL written to the same directory, followed by that signed EXE making outbound HTTP to a young look-alike-CDN domain — survives infrastructure rotation and payload swaps. IOC hunts (the published hashes, the three domains, one IP) are included for immediate coverage but treated as perishable.

Defender priority: Hunt for signed Microsoft/Sogou binaries loading an unsigned or co-located DLL and then beaconing to look-alike CDN domains (*-cdn.it.com, icloud-cdn.net). A trusted process side-loading a freshly written DLL and immediately calling out is the single most reliable Twill Typhoon signal — anchor detection there, not on the rotating hashes.

02

Source Review & Web Hunter Notes

TierSourceKey FindingCarry Fwd
1Darktrace — "Chinese APT Campaign … Updated FDMTP Backdoor" (15 May 2026)Primary report. Full IOC set: hashes, 3 domains, 1 IP, 5-step attack chain, DMTP C2 mechanics, abused binaries, persistence keys.yes
2Industrial Cyber — Twill Typhoon DLL side-loading FDMTP (APAC)Corroborates chain, binaries, yahoo-cdn.it.com, /GetCluster pattern, plugin modules, finance targeting.yes
2Infosecurity Magazine — Mustang Panda FDMTP APJConfirms icloud-cdn.net 5-min poll, FDMTP v3.2.5.1, IME registry persistence, alias mapping.yes
2SecurityWeek — Chinese APTs expand targets / update backdoorsConfirms ClickOnce + VS Hosting abuse, modular .NET capability set, APAC/Japan + finance scope.partial
3IBM X-Force Exchange (OSINT collection)Auth-gated; no atomic IOCs extractable from public fragment. Listed for provenance only.no

Provenance note: Every atomic IOC in §4/§10 traces to Darktrace (hashes, IP, all three domains) corroborated by Industrial Cyber and Infosecurity Magazine. No IOCs were synthesized. Where an atomic value could not be sourced, the pack relies on behavioral detection instead.

03

Hunt Brief & Attack Chain

Hunt hypotheses (ordered by fidelity)

  1. H1 (high): A signed, legitimate binary (biz_render.exe, vshost.exe, dfsvc.exe) loads a DLL that was written to disk minutes earlier and/or resides in a non-standard path — classic side-load. T1574.002
  2. H2 (high): One of the abused binaries (or any process) makes outbound HTTP to a look-alike CDN domain (*yahoo-cdn*, icloud-cdn[.]net, *-cdn.it.com). T1071.001 / T1036.005
  3. H3 (high): Outbound request whose URI contains /GetCluster with protocol=DotNet-TcpDmtp or a Verify_Token: Dmtp header — FDMTP C2 registration. T1071.001
  4. H4 (medium): Named malicious DLLs written to disk (dnscfg.dll, browser_host.dll, Client.TcpDmtp.dll, Client.DmtpFrame.dll, the VS sync DLL). T1105 / T1574.002
  5. H5 (medium): Registry persistence under HKCU\Software\Microsoft\IME\{id} or the TypeLib COM CLSID, or scheduled-task creation by a side-loaded process. T1547.001 / T1053.005 / T1546
  6. H6 (medium): Atomic IOC matches — published hashes, the three domains, IP 154.223.58[.]142. Perishable.
  7. H7 (low): A non-browser, signed binary beaconing on a fixed ~5-minute interval (update-channel polling). T1071.001 / beacon cadence

Attack chain

StepBehaviorTelemetryHunt Angle
1 · Initial accessSpear-phish leads host to retrieve staged filesDnsRequest, NetworkConnectIP4First contact with look-alike CDN domain
2 · Retrieve legit EXEDownload signed biz_render/vshost/dfsvc.exePeFileWritten, FileCreateInfoTrusted EXE landing in user-writable / odd path
3 · Retrieve .configMatching dfsvc.exe.config / .config fileFileCreateInfoEXE + .config + DLL co-written within minutes
4 · Retrieve malicious DLLSide-load DLL (dnscfg.dll, browser_host.dll …); repeated pulls over daysPeFileWritten, ImageHashUnsigned DLL beside signed EXE; module-load
5 · Execute / side-loadSigned EXE loads rogue DLL → .NET runtime in-process → FDMTPProcessRollup2, ImageFileName, module loadSigned parent, anomalous child DLL + clr.dll load
6 · C2 (DMTP)/GetCluster?protocol=DotNet-TcpDmtp, header Verify_Token: Dmtp; ~5-min pollNetworkConnectIP4, DnsRequestURI/header signature + look-alike CDN + cadence
7 · PersistHKCU\…\IME\{id}, TypeLib COM CLSID, scheduled taskRegGenericValueUpdate, ScheduledTaskRegisteredPersistence written by side-loaded process
04

Consolidated IOC Table

All values below are reproduced verbatim from cited primary sources (Darktrace / Industrial Cyber / Infosecurity Magazine). Network IOCs are defanged. Infrastructure rotates — treat hashes/domains as perishable and lead with the behavioral hunts in §8.

TypeValueConfActionContext
domainwww.icloud-cdn[.]nethighdetectApple-impersonating CDN; ~5-min update poll (Infosecurity / Darktrace)
domainwww.yahoo-cdn.it[.]comhighdetectYahoo-impersonating CDN payload host (Darktrace / Industrial Cyber)
domainyahoo-cdn.it[.]comhighdetectApex of Yahoo look-alike CDN (Darktrace)
ipv4154.223.58[.]142mediumhuntAssociated C2/staging infrastructure (Darktrace)
md5 (Test.zip)fc3959ebd35286a82c662dc81ca658cbhighdetectStaging archive (Darktrace)
md5 (dnscfg.dll)b2c8f1402d336963478f4c5bc36c961ahighdetectMalicious side-load DLL paired w/ dfsvc.exe (Darktrace)
md5 (browser_host.dll)c17f39d25def01d5c87615388925f45ahighdetectSide-load DLL via biz_render.exe / Sogou Pinyin (Darktrace)
md5 (Client.TcpDmtp.dll)c52b4a16d93a44376f0407f1c06e0bmediumhuntFDMTP DMTP transport module (Darktrace; hash as printed)
md5 (Client.DmtpFrame.dll)482cc72e01dfa54f30efe4fefde5422dhighdetectFDMTP framing module (Darktrace)
md5 (VisualStudio Sync DLL)c650a624455c5222906b60aac7e57d48highdetectMicrosoft.VisualStudio.HostingProcess.Utilities.Sync.dll side-load via vshost.exe (Darktrace)
md5 (Persist.Extra)162F69FE29EB7DE12B684E979A446131highdetectFDMTP persistence plugin (Darktrace)
md5 (Persist.Registry)067FBAD4D6905D6E13FDC19964C1EA52highdetectFDMTP registry-persistence plugin (Darktrace)
md5 (Persist.WpTask)DF3437C88866C060B00468055E6FA146highdetectFDMTP scheduled-task persistence plugin (Darktrace)
md5 (Assist)2CD781AB63A00CE5302ED844CFBECC27highdetectFDMTP assist/loader module (Darktrace)
filename (legit, abused)biz_render.exehighhuntSogou Pinyin IME binary abused for side-load
filename (legit, abused)vshost.exe / vhost.exehighhuntVisual Studio hosting process abused for side-load
filename (legit, abused)dfsvc.exehighhunt.NET ClickOnce engine abused for side-load
uri pattern/GetCluster?protocol=DotNet-TcpDmtp&tag={0}&uid={1}highdetectFDMTP C2 registration URI (Darktrace / Industrial Cyber)
http headerVerify_Token: DmtphighdetectCustom FDMTP C2 header (Darktrace)
registryHKCU\Software\Microsoft\IME\{id}mediumhuntFDMTP persistence key (Darktrace / Infosecurity)
registryHKCU\Software\Classes\TypeLib\{9E175B61-F52A-11D8-B9A5-505054503030}\1.0\1\Win64mediumhuntCOM TypeLib persistence (Darktrace)
05

Affected Surface & Telemetry Matrix

SurfaceRequired TelemetryPriorityGap Risk
Windows endpoints (user workstations)ProcessRollup2, PeFileWritten, FileCreateInfo, module-loadCriticalLow — core EDR
DLL module-load visibilityImageHash / loaded-module eventsHighMedium — not all tenants log module loads
Egress / DNSDnsRequest, NetworkConnectIP4HighLow
HTTP URI / header inspectionProxy / TLS-inspect / web-gateway logsHighHigh — URI/header hidden without proxy or TLS inspect
Registry & scheduled tasksRegGenericValueUpdate, ScheduledTaskRegisteredMediumLow

Gap: The strongest C2 signatures (/GetCluster URI, Verify_Token: Dmtp header) live in HTTP request content. Without a proxy or TLS inspection, fall back to domain/IP + the side-load behavioral hunt (Q1/Q2).

06

ATT&CK Mapping

TacticTechniqueObserved BehaviorQuery / Control
Initial AccessT1566 PhishingSpear-phish leading to staged retrievalNative §7 / Q2
Command & ControlT1105 Ingress Tool TransferRepeated EXE/config/DLL pulls from CDN look-alikesQ2, Q4
Defense EvasionT1574.002 DLL Side-LoadingSigned EXE loads rogue co-located DLLQ1
Defense EvasionT1036.005 Match Legit Name/LocationInfra + binaries impersonate Yahoo/Apple/MS/SogouQ2, IOA
ExecutionT1106 Native API.NET runtime loaded in-process by side-load DLLQ1, Q5
Defense EvasionT1620 Reflective Code LoadingNext-stage .NET pulled directly into memoryQ5
Defense EvasionT1140 / T1027 Deobf / ObfuscationRuntime string decryption; obfuscated .NETNative §7
PersistenceT1547.001 Registry Run/IME keyHKCU\…\IME\{id}Q6
PersistenceT1053.005 Scheduled TaskFDMTP WpTask plugin creates taskQ6, Native §7
PersistenceT1546 Event-Triggered (COM TypeLib)TypeLib CLSID persistenceQ6
DiscoveryT1082 / T1007 / T1622 System/Service/DebuggerSystem fingerprinting, AV/domain/hardware enumNative §7
Command & ControlT1071.001 App-Layer (Web)/GetCluster + Verify_Token: DmtpQ3
Command & ControlT1571 / T1095 Non-Standard Port / Non-App-LayerCustom DMTP over TCPQ3, Q7
07

Native Audit-Log Hunts

Checks runnable without CQL, for tenants lacking full module-load or proxy telemetry:

  • Sysmon Event ID 7 (Image Loaded): alert when biz_render.exe, vshost.exe, or dfsvc.exe load a DLL with Signed=false or a publisher other than the host binary's.
  • Sysmon Event ID 11 (File Create): a .exe, a matching .config, and a .dll written to the same user-writable directory within a short window.
  • Sysmon Event ID 13 (Registry Set): writes to HKCU\Software\Microsoft\IME\ sub-keys or the TypeLib CLSID {9E175B61-F52A-11D8-B9A5-505054503030} by a non-IME process.
  • Windows Security 4698 (Scheduled Task Created): task registered with an action pointing at a user-profile path or one of the abused binaries.
  • Web-gateway / proxy logs: any request to *yahoo-cdn*, icloud-cdn[.]net, *-cdn.it.com, or a URI containing /GetCluster / header Verify_Token: Dmtp.
  • DNS resolver logs: resolutions of the three published domains or newly-registered *-cdn* look-alikes of Yahoo/Apple.
08

CrowdStrike LogScale CQL Hunt Queries

Pick your tenant's cloud first — every "Open in Falcon" button below uses this selection.
Q1 · Abused legit binary writing/co-located with a fresh DLL (side-load setup)
CONF HIGHFP MEDCOST LOW

Looks for: a PE DLL written to disk by, or beside, one of the three abused legitimate binaries — the file-staging stage of the side-load. FP: legitimate VS / Sogou / ClickOnce updates write DLLs too; scope to user-writable paths and pair with Q2 egress.

// HUNT: Abused legit binary co-writing a DLL (side-load staging)
// MITRE: T1574.002, T1105
// CONF: high  FP: med  COST: low | REQUIRES: PeFileWritten
// FALSE POSITIVES: legitimate Visual Studio / Sogou / ClickOnce updates
// TUNING: restrict to \Users\ \AppData\ \Temp\ \ProgramData\ ; exclude signed publisher update dirs
#event_simpleName=PeFileWritten
| TargetFileName=/\.dll$/i
| ContextBaseFileName=/^(biz_render|vshost|vhost|dfsvc)\.exe$/i
| FilePath=/\\(Users|AppData|Temp|ProgramData|Public)\\/i
| table([@timestamp, ComputerName, UserName, ContextBaseFileName, TargetFileName, FilePath, SHA256HashData], limit=200)
Q2 · Outbound to CDN-impersonating look-alike domains
CONF HIGHFP LOWCOST LOW

Looks for: DNS resolution of the published Yahoo/Apple look-alike CDN domains plus the generic *-cdn.it.com pattern. FP: low — these strings are actor-specific; the broad -cdn.it.com arm may need review.

// HUNT: DNS to Twill Typhoon CDN-impersonating infrastructure
// MITRE: T1071.001, T1036.005
// CONF: high  FP: low  COST: low | REQUIRES: DnsRequest
// FALSE POSITIVES: rare; review the generic -cdn.it.com arm before alerting
#event_simpleName=DnsRequest
| DomainName=/(^|\.)(yahoo-cdn\.it\.com|icloud-cdn\.net)$|(-cdn\.it\.com)$/i
| table([@timestamp, ComputerName, UserName, DomainName, ContextBaseFileName], limit=200)
Q3 · Non-browser signed binary beaconing to staging IP / look-alike infra
CONF HIGHFP MEDCOST LOW

Looks for: network connections from the abused binaries (FDMTP host process) or to the published C2 IP — the DMTP beacon. FP: medium; the abused binaries legitimately exist, so confirm against domain (Q2) and the URI signature where proxy logs allow.

// HUNT: FDMTP C2 — side-load host process beacon / published staging IP
// MITRE: T1071.001, T1571, T1095
// CONF: high  FP: med  COST: low | REQUIRES: NetworkConnectIP4
// FALSE POSITIVES: legit dfsvc/vshost net activity; confirm against Q2 domains
// TUNING: drop the IP arm once it ages out; keep the process arm
#event_simpleName=NetworkConnectIP4
| (RemoteAddressIP4="154.223.58.142" OR ContextBaseFileName=/^(biz_render|vshost|vhost|dfsvc)\.exe$/i)
| RemotePort!=0
| table([@timestamp, ComputerName, UserName, ContextBaseFileName, RemoteAddressIP4, RemotePort], limit=200)
Q4 · Named malicious FDMTP DLLs / staging archive on disk
CONF MEDFP LOWCOST LOW

Looks for: the named malicious DLLs and staging archive by filename or published hash. FP: low; filenames like WindowsBase.dll are also legitimate, so the hash arm and path context disambiguate.

// HUNT: FDMTP named DLLs / staging archive by name or hash
// MITRE: T1105, T1574.002
// CONF: med  FP: low  COST: low | REQUIRES: PeFileWritten
// FALSE POSITIVES: legit WindowsBase.dll/Client.dll — rely on hash + path
#event_simpleName=/PeFileWritten|NewExecutableWritten/
| (TargetFileName=/(dnscfg|browser_host|Client\.TcpDmtp|Client\.DmtpFrame|client\.core|Persist\.(WpTask|registry|extra)|Assist)\.dll$/i
   OR TargetFileName=/Microsoft\.VisualStudio\.HostingProcess\.Utilities\.Sync\.dll$/i
   OR MD5HashData=/^(b2c8f1402d336963478f4c5bc36c961a|c17f39d25def01d5c87615388925f45a|482cc72e01dfa54f30efe4fefde5422d|c650a624455c5222906b60aac7e57d48|fc3959ebd35286a82c662dc81ca658cb)$/i)
| table([@timestamp, ComputerName, UserName, TargetFileName, FilePath, MD5HashData, SHA256HashData], limit=max)
Q5 · Abused binary loading the CLR from a user-writable path (in-process .NET)
CONF HIGHFP MEDCOST MED

Looks for: the side-load host process spawning from / running in a user-writable directory — the EXE staged outside its normal install location. FP: medium; ClickOnce/VS legitimately run from profile paths, so pair with Q1/Q2 within the same host+window.

// HUNT: Abused binary executing from user-writable path (staged side-load)
// MITRE: T1574.002, T1106, T1620
// CONF: high  FP: med  COST: med | REQUIRES: ProcessRollup2
// FALSE POSITIVES: ClickOnce dfsvc.exe legitimately runs from profile; correlate w/ Q1+Q2
// TUNING: join on aid to Q2 domain hits within a 24h window before alerting
#event_simpleName=/ProcessRollup2|SyntheticProcessRollup2/
| ImageFileName=/\\(biz_render|vshost|vhost)\.exe$/i
| ImageFileName=/\\(Users|AppData|Temp|ProgramData|Public)\\/i
| table([@timestamp, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName, SHA256HashData], limit=200)
Q6 · FDMTP persistence — IME key / TypeLib CLSID / scheduled task
CONF MEDFP MEDCOST LOW

Looks for: registry persistence under the IME path or the published TypeLib CLSID. FP: medium — the IME tree is also touched by legitimate IME software; the specific TypeLib GUID is high-fidelity.

// HUNT: FDMTP registry persistence (IME key / TypeLib CLSID)
// MITRE: T1547.001, T1546
// CONF: med  FP: med  COST: low | REQUIRES: RegGenericValueUpdate / AsepValueUpdate
// FALSE POSITIVES: genuine IME installs touch HKCU\...\IME — TypeLib GUID arm is high-fidelity
// TUNING: alert on the TypeLib GUID arm; treat the IME arm as hunt-only
#event_simpleName=/RegGenericValueUpdate|AsepValueUpdate|RegKeyCreate/
| RegObjectName=/(Software\\Microsoft\\IME\\|TypeLib\\\{9E175B61-F52A-11D8-B9A5-505054503030\})/i
| table([@timestamp, ComputerName, UserName, RegObjectName, RegValueName, RegStringValue], limit=200)
Q7 · Fixed-interval (~5 min) beacon cadence from a non-browser binary
CONF LOWFP MEDCOST HIGH

Looks for: repetitive outbound connections from the abused binaries consistent with the ~5-minute update-channel poll. FP: medium — many apps poll on a cadence; use as a triage aid, not a standalone alert.

// HUNT: Periodic beacon cadence from FDMTP side-load host process
// MITRE: T1071.001, T1095
// CONF: low  FP: med  COST: high | REQUIRES: NetworkConnectIP4
// FALSE POSITIVES: legit update/telemetry pollers — triage aid only, not standalone
// TUNING: review hosts with conn_count >= 10 to few remotes over the window
#event_simpleName=NetworkConnectIP4
| ContextBaseFileName=/^(biz_render|vshost|vhost|dfsvc)\.exe$/i
| groupBy([ComputerName, ContextBaseFileName, RemoteAddressIP4], function=[count(as=conn_count), min(@timestamp, as=first), max(@timestamp, as=last)])
| conn_count>=10
| table([ComputerName, ContextBaseFileName, RemoteAddressIP4, conn_count, first, last], limit=200)
09

CrowdStrike Custom IOA Recommendations

IOA-1 · Trusted binary side-loading from user-writable path

Rule type: Process Creation. Pattern: Image Filename matches (biz_render|vshost|vhost|dfsvc)\.exe AND Image Path under \Users\ / \AppData\ / \Temp\ / \ProgramData\. Action: Detect (escalate to Block after baseline). Exclusions: signed publisher update/installer directories.

IOA-2 · Network connection to FDMTP C2 URI signature

Rule type: Network Connection / DNS. Pattern: Domain matches yahoo-cdn\.it\.com / icloud-cdn\.net / -cdn\.it\.com. Action: Detect & alert. Exclusions: none expected; review the generic -cdn.it.com arm against your environment first.

IOA-3 · Named FDMTP DLL written to disk

Rule type: File Write. Pattern: Target filename matches the FDMTP DLL set in Q4. Action: Detect. Exclusions: exclude legitimate WindowsBase.dll in system paths.

Promotion path: Q1, Q2, Q4 are the strongest IOA candidates (high CONF, low/med FP). Q3/Q5/Q6 stay Investigate-only until baselined. Q7 is triage-aid only.

10

Machine-Readable IOC Appendix

Grouped quick-copy blocks. All atomic values are sourced from the cited reports; defang is removed in the import-ready CSV.

Falcon IOC Management CSVbulk import
type,value,action,severity,expiration,description,tags
domain,icloud-cdn.net,detect,high,2026-12-21,Twill Typhoon Apple-impersonating CDN,campaign:TwillTyphoon
domain,yahoo-cdn.it.com,detect,high,2026-12-21,Twill Typhoon Yahoo-impersonating CDN,campaign:TwillTyphoon
ipv4,154.223.58.142,detect,high,2026-09-21,Twill Typhoon C2/staging IP,campaign:TwillTyphoon
md5,fc3959ebd35286a82c662dc81ca658cb,detect,critical,2027-06-21,FDMTP staging archive Test.zip,campaign:TwillTyphoon
md5,b2c8f1402d336963478f4c5bc36c961a,detect,critical,2027-06-21,FDMTP dnscfg.dll sideload,campaign:TwillTyphoon
md5,c17f39d25def01d5c87615388925f45a,detect,critical,2027-06-21,FDMTP browser_host.dll sideload,campaign:TwillTyphoon
md5,482cc72e01dfa54f30efe4fefde5422d,detect,critical,2027-06-21,FDMTP Client.DmtpFrame.dll,campaign:TwillTyphoon
md5,c650a624455c5222906b60aac7e57d48,detect,critical,2027-06-21,FDMTP VisualStudio Sync DLL sideload,campaign:TwillTyphoon
md5,162F69FE29EB7DE12B684E979A446131,detect,critical,2027-06-21,FDMTP Persist.Extra,campaign:TwillTyphoon
md5,067FBAD4D6905D6E13FDC19964C1EA52,detect,critical,2027-06-21,FDMTP Persist.Registry,campaign:TwillTyphoon
md5,DF3437C88866C060B00468055E6FA146,detect,critical,2027-06-21,FDMTP Persist.WpTask,campaign:TwillTyphoon
md5,2CD781AB63A00CE5302ED844CFBECC27,detect,critical,2027-06-21,FDMTP Assist module,campaign:TwillTyphoon
Behavioral Signaturesdurable
Signed EXE (biz_render.exe / vshost.exe / dfsvc.exe) loads an
  unsigned or co-located DLL from a user-writable path  -> side-load
EXE + matching .config + DLL written to same dir within minutes  -> staging
HTTP URI contains:  /GetCluster?protocol=DotNet-TcpDmtp&tag=...&uid=...
HTTP request header:  Verify_Token: Dmtp
Look-alike CDN domains:  *yahoo-cdn*, icloud-cdn[.]net, *-cdn.it.com
~5-minute fixed-interval beacon from a non-browser signed binary
.NET CLR loaded in-process by a side-load host then memory-only stage
Named Tooling & FilesFDMTP
Backdoor:       FDMTP (modular .NET RAT, observed v3.2.5.1)
Abused legit:   biz_render.exe (Sogou Pinyin IME)
                vshost.exe / vhost.exe (Visual Studio Hosting)
                dfsvc.exe (.NET ClickOnce engine)
Malicious DLLs: dnscfg.dll, browser_host.dll, Client.TcpDmtp.dll,
                Client.DmtpFrame.dll, client.core.dll,
                Persist.WpTask.dll, Persist.registry.dll,
                Persist.extra.dll, Assist.dll, WindowsBase.dll,
                Microsoft.VisualStudio.HostingProcess.Utilities.Sync.dll
Config/stage:   dfsvc.exe.config, config.etl, checksum.bin/.etl,
                version.txt, Test.zip
Persistence:    HKCU\Software\Microsoft\IME\{id}
                HKCU\Software\Classes\TypeLib\{9E175B61-F52A-11D8-B9A5-505054503030}\1.0\1\Win64
ASR / Hardening Auditverify
# ASR rules relevant to this campaign (Defender)
# 56a863a9-875e-4185-98a7-b882c64b5ce5  Block untrusted/unsigned from USB
# 01443614-cd74-433a-b99e-2ecdc07bfc25  Block executables unless prevalence/age/trusted
# d1e49aac-8f56-4280-b9ba-993a6d77406c  Block process creations from PSExec/WMI
Get-MpPreference | Select -Expand AttackSurfaceReductionRules_Ids
Get-MpPreference | Select -Expand AttackSurfaceReductionRules_Actions
# Confirm SmartScreen + signature enforcement
Get-MpComputerStatus | Select AMRunningMode, RealTimeProtectionEnabled
11

Detection Validation Gates

GateCheckPass Criteria
Telemetry readyPeFileWritten, ProcessRollup2, DnsRequest, NetworkConnectIP4, registry events flowingAll five event types present in last 24h
Module-load coverageImage/module-load events available (for Q1/Q5 fidelity)Confirmed or documented gap; fall back to file-write hunts
Proxy / HTTP contentURI + header visibility for /GetCluster / Verify_TokenAvailable, or documented gap → rely on Q2/Q3
Benign baselineRun Q1/Q5 over 7d; catalog legit VS/Sogou/ClickOnce noiseExclusions written before promotion
Positive testBenign signed EXE side-loading a test DLL from %TEMP%Q1 fires; openFalcon link resolves
PromotionQ1/Q2/Q4 → Custom IOA after baseline; Q3/Q5/Q6 stay huntFP rate acceptable in pilot ring
12

Hardening — Tiered

Immediate (this week — low risk)
  • Block the published infrastructure at proxy/DNS/firewall: the three domains and the C2 IP. (M1037 Filter Network Traffic)
  • Enable Defender ASR "Block executable files from running unless they meet a prevalence/age/trusted-list criterion" (01443614-…) and the unsigned-from-USB rule (56a863a9-…) in Block mode. (M1038 Execution Prevention; CIS Win11 §18 / MS Security Baseline)
  • SmartScreen + signature enforcement on, so freshly-downloaded unsigned DLLs/EXEs are flagged. (M1042 Disable/Remove Feature)
Near term (1–4 weeks — pilot first)
  • WDAC / AppLocker DLL rules: enforce DLL-load policy so signed binaries cannot load unsigned DLLs from user-writable paths — directly defeats the side-load. (M1038; MS WDAC guidance) pilot — app-compat risk
  • Remove/uninstall unused IME and Visual Studio hosting components from non-developer fleets so biz_render.exe / vshost.exe aren't present to abuse. (M1042)
  • Newly-Registered-Domain & look-alike blocking at the proxy for *-cdn* typo-squats of major brands. (M1037)
Strategic (1–3 months — architectural)
  • Full WDAC in enforced mode with a managed publisher allow-list across the fleet. (M1038)
  • Egress TLS inspection on a proxy to expose the /GetCluster URI and Verify_Token: Dmtp header for content-based detection. (M1037) privacy/coordination
  • Phishing-resistant email controls + user training targeting the spear-phish initial access. (M1017 / M1031)
13

Deployable Playbooks

P1 · Enable ASR rules (PowerShell)

# Block executables unless they meet prevalence/age/trusted-list criteria
Add-MpPreference -AttackSurfaceReductionRules_Ids 01443614-cd74-433a-b99e-2ecdc07bfc25 -AttackSurfaceReductionRules_Actions Enabled
# Block untrusted and unsigned processes that run from USB
Add-MpPreference -AttackSurfaceReductionRules_Ids 56a863a9-875e-4185-98a7-b882c64b5ce5 -AttackSurfaceReductionRules_Actions Enabled
# Verify
Get-MpPreference | Select-Object -ExpandProperty AttackSurfaceReductionRules_Ids

P2 · WDAC DLL-enforcement skeleton (block unsigned DLL loads)

# Build a base policy in enforced mode, then enable the option that also
# enforces DLL load rules (Option 0 + DLL enforcement). Pilot in Audit first.
$pol = "C:\WDAC\TwillTyphoon_DLLenforce.xml"
New-CIPolicy -FilePath $pol -Level Publisher -UserPEs -ScanPath C:\Windows
Set-RuleOption -FilePath $pol -Option 0          # Enabled:UMCI
Set-RuleOption -FilePath $pol -Option 3 -Delete  # remove Audit mode -> enforce
ConvertFrom-CIPolicy -XmlFilePath $pol -BinaryFilePath C:\WDAC\TwillTyphoon.cip
# Stage C:\WDAC\TwillTyphoon.cip via CI policy refresh / Intune; pilot ring first.

P3 · Block infrastructure (DNS sinkhole / hosts — pilot)

# Proxy/firewall block list (preferred). Sample hosts-level fallback:
0.0.0.0  yahoo-cdn.it.com
0.0.0.0  www.yahoo-cdn.it.com
0.0.0.0  icloud-cdn.net
0.0.0.0  www.icloud-cdn.net
# Firewall: deny egress to 154.223.58.142

⚠ Pilot before fleet-wide: WDAC DLL enforcement can break legitimate apps. Deploy in Audit, review CodeIntegrity/Operational 3076 events, then enforce on a ring.

14

Containment Runbook

PhaseActionsOwnerEvidence
IsolateNetwork-contain host via Falcon; preserve memory if feasible (FDMTP is memory-staged)SOC L2Containment timestamp, host ID
ScopeRun Q2/Q4 environment-wide; pivot on aid of any hit to find sibling hosts; check proxy logs for /GetClusterThreat HuntHit list, IPs/domains contacted
EradicateRemove side-loaded DLLs, staged EXE/.config, scheduled task, and registry persistence (IME key + TypeLib CLSID)IR / EndpointFile + registry artifacts collected
EradicateRotate credentials used on host; assume collection occurred (espionage)IAMReset log
RecoverReimage; restore from known-good; re-baseline after WDAC/ASR appliedEndpointRebuild ticket
ReportBlock IOCs (§10 CSV), brief stakeholders, file intel updateSOC LeadThis pack + IOC import receipt
15

Detection Coverage Map

TechniqueBehaviorCQLIOACoverage
T1574.002 Side-LoadingSigned EXE loads rogue co-located DLLQ1, Q5IOA-1Good
T1071.001 C2 (look-alike CDN)DNS/connect to impersonating CDNQ2, Q3IOA-2Good
T1071.001 C2 (URI/header)/GetCluster + Verify_Token: DmtpNative §7Partial — needs proxy/TLS inspect
T1105 Ingress TransferNamed DLL / archive writtenQ4IOA-3Good
T1547.001 / T1546 PersistenceIME key / TypeLib CLSIDQ6Partial — IME arm noisy
T1053.005 Scheduled TaskWpTask plugin creates taskNative §7Partial
T1620 Reflective LoadMemory-only .NET stageQ5 (proxy)GAP — in-memory only
T1566 Initial AccessSpear-phishGAP — email-side, out of EDR scope

Validation: baseline Q1/Q5 over 7 days to capture legitimate VS/Sogou/ClickOnce DLL loads before promoting to IOA. The two GAP rows (reflective .NET load; spear-phish) are not EDR-process-detectable here — cover them via memory-scan/AMSI and email security respectively.

16

Hunt Summary Ticket

TITLE:      Twill Typhoon (Mustang Panda) — Updated FDMTP Backdoor via DLL Side-Loading
SEVERITY:   HIGH — Nation-state espionage, active (late Sep 2025 – Apr 2026)
SCOPE:      Windows endpoints; APAC/Japan + finance targeting; trusted-process side-load
HYPOTHESIS: Signed legit binaries (biz_render/vshost/dfsvc.exe) side-load malicious DLLs
            from CDN-impersonating infra, staging a modular .NET RAT (FDMTP) over DMTP C2
QUERIES:    Q1 side-load staging | Q2 look-alike CDN DNS | Q3 C2 beacon/IP
            Q4 named DLL/archive | Q5 staged-path exec | Q6 persistence | Q7 cadence
DO FIRST:   Run Q2 + Q4 env-wide; block 3 domains + 154.223.58.142; enable ASR (P1)
FINDINGS:   <fill: hosts, hits, C2 contacted>
GAPS:       Reflective in-memory .NET stage; spear-phish initial access (email-side)
ACTIONS:    Isolate -> scope via aid -> eradicate DLL/task/registry -> reimage -> block IOCs
OWNER:      HuntPack
VERSION:    v0.2 · 2026-06-21
17

Changelog

v0.22026-07-24CQL correctness pass. All table() calls now carry an explicit row limit: the default is 200 and truncation is silent, so a capped result was indistinguishable from a complete one. Atomic-IOC sweeps (filters over 5+ hashes or C2 IPs) use limit=max so a wide infection is never silently under-scoped; behavioural hunts use limit=200, where exceeding the cap indicates the query needs tuning. Where present, event names that do not exist in the Falcon data model were corrected (e.g. ServiceInstalled is a Sysmon concept, not a Falcon event; ElfFileWritten is ELFFileWritten) — such queries could never return a row. No detection logic, fields, or IOCs changed.
v0.12026-06-21Initial HuntPack — full v2 pipeline. 7 CQL hunts, 3 IOA recs, behavioral-first detection anchored to DLL side-loading + CDN-impersonating DMTP C2. IOCs sourced from Darktrace / Industrial Cyber / Infosecurity Magazine.
18

References

TierSourceUsed ForAccess Date
1Darktrace — Updated FDMTP BackdoorPrimary IOCs, chain, C2 mechanics2026-06-21
2Industrial Cyber — Twill Typhoon DLL side-loadingChain, binaries, GetCluster, finance scope2026-06-21
2Infosecurity Magazine — Mustang Panda FDMTP APJicloud-cdn poll, FDMTP v3.2.5.1, aliases2026-06-21
2SecurityWeek — Chinese APTs update backdoorsClickOnce/VS abuse, capability set, scope2026-06-21
3IBM X-Force Exchange — OSINT collectionProvenance reference (auth-gated)2026-06-21