TwoPence is an implant framework associated with North Korean state-sponsored operations, including activity linked to STARDUST CHOLLIMA and reporting that places it within the broader BlueNorOff/Lazarus ecosystem. It is used to establish an initial foothold or beachhead on compromised systems and includes modular components, including an XorDNS variant used as a service-executed DLL implant. The framework is derived in part from a shared malware development repository leveraged by North Korean operators involved in financially motivated intrusion activity. TwoPence has been observed in campaigns aligned with long-running DPRK cyber operations that combine covert access, post-compromise control, and operational flexibility across victim environments. High-confidence reporting supports its role as an implant or backdoor framework rather than as ransomware or destructive malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The proxy requires an encrypted command line argument for its source and destination Internet Protocol (IP) addresses and has command and control (C2) functionality to retrieve and set the destination IP.
This report looks at the malware samples known as VIVACIOUSGIFT that is used by advanced persistent threat (APT) cyber actors as a network proxy tool.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family associated with BlueNorOff operations.
TwoPence is an implant framework used by North Korean threat actors, notably STARDUST CHOLLIMA, for persistent access and command and control. It includes components such as XorDNS for C2 communications and has been used in financially-motivated cybercrime operations.
Framework used to establish initial access or a beachhead in FASTCash ATM jackpotting operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.