WINDYTWIST.SEA is a backdoor described as a C-language version of WINDYTWIST. It has been observed as an additional payload delivered by the CORNFLAKE.V3 backdoor in ClickFix campaigns tracked by Mandiant and associated with UNC5518. In this activity, victims are lured via fraudulent CAPTCHA pages reached through illicit advertising and search engine poisoning, then tricked into executing a malicious PowerShell command that deploys CORNFLAKE.V3; CORNFLAKE.V3 can subsequently deliver WINDYTWIST.SEA. Reported capabilities of WINDYTWIST.SEA include relaying TCP traffic, providing a reverse shell, executing commands, and removing itself. Select versions have also been observed attempting lateral movement within the infected network. The provided content does not include specific indicators of compromise for WINDYTWIST.SEA.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...CORNFLAKE.V3 also enables the execution of additional payloads, including... the WINDYTWIST.SEA backdoor...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Secondary backdoor payload delivered/executed by CORNFLAKE.V3.
A C-based backdoor supporting TCP relay, reverse shell, command execution, self-removal, and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.