TwoFace
Aliases: HighShell, HyperShell, Minion, SEASHARPEE
- Malware type
- webshell, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 12:48:52
Context
According to Unit42, TwoFace is a two-staged (loader+payload) webshell, written in C# and meant to run on webservers with ASP.NET. The author of the initial loader webshell included legitimate and expected content that will be displayed if a visitor accesses the shell in a browser, likely to remain undetected. The code in the loader webshell includes obfuscated variable names and the embedded payload is encoded and encrypted. To interact with the loader webshell, the threat actor uses HTTP POST requests to the compromised server. The secondary webshell, which we call the payload, is embedded within the loader in encrypted form and contains additional functionality that we will discuss in further detail. When the threat actor wants to interact with the remote server, they provide data that the loader will use to modify a decryption key embedded within the loader that will be in turn used to decrypt the embedded TwoFace payload. Commands supported by the payload are execution of programs, up-, download and deletion of files and capability to manipulate MAC timestamps.
Detection coverage
- 1 YARA rules
Detection rules
- VOLEXITY_Apt_Webshell_Aspx_Sportsball (yara-rule)
Reports & references
- Palo Alto Unit 42 — Unit42 Twoface Webshell Persistent Access Point Lateral Movement (report)
- secureworks.com — Cobalt Gypsy (report)
- Palo Alto Unit 42 — Evasive Serpens (report)
- malpedia.caad.fkie.fraunhofer.de — Asp.Twoface (report)
- cyware.com — Apt34 The Helix Kitten Cybercriminal Group Loves To Meow Middle Eastern And International Organizations 48Ae (report)
- youtube.com — Watch (report)
- cyber.gov.au — Acsc Advisory 2020 008 Copy Paste Compromises (report)
- go.recordedfuture.com — Cta 2020 0312 (report)
- drive.google.com — View (report)
- go.recordedfuture.com — Mtp 2021 1214 (report)
- recordedfuture.com — Full Spectrum Detections Five Popular Web Shells (report)
- ptsecurity.com — Incident Response Polar Ransomware Apt27 (report)
- Palo Alto Unit 42 — Unit42 Oilrig Performs Tests Twoface Webshell (report)
- youtube.com — Watch (report)
- zdnet.com — Source Code Of Iranian Cyber Espionage Tools Leaked On Telegram (report)
- web.archive.org — Summit Archive 1574947864 (report)
- sans.org — Summit Archive 1536345486 (report)