TwoFace is a multi-stage ASP.NET webshell family associated with the Iranian-aligned OilRig threat group, also tracked as APT34 and Helix Kitten. It is designed for persistent post-exploitation access on compromised Microsoft IIS and Exchange servers and was used in intrusions against organizations in the Middle East, including operations linked to targeting of Israeli institutions and other regional government, education, and enterprise environments.
TwoFace is characterized by a layered architecture consisting of a loader component and an embedded payload webshell. The loader accepts HTTP POST data, derives a decryption key from operator-supplied input, decrypts the embedded payload, and can save or remove that payload on the server. This design helps conceal the functional shell until the operator chooses to deploy it. The payload component authenticates the operator and supports remote command execution, file upload and download, writing decoded content to disk, file deletion, and timestamp manipulation. Related variants and closely associated names include TwoFace++, HyperShell as a loader-side variant, HighShell as a payload-side variant, and Minion as a related webshell with overlapping functionality.
Observed operator activity shows TwoFace being used for long-term persistence, credential theft, and lateral movement. Threat actors used it to execute reconnaissance commands, enumerate privileged groups, dump credentials with Mimikatz, and deploy additional webshells to other Exchange servers. The malware was also used alongside other post-exploitation tooling and related webshells such as IntrudingDivisor, RunningBee, LittleFace, and the IIS backdoor RGDoor. Reporting on leaked OilRig tooling indicates continued development of the family, including modular enhancements in related HighShell versions and deliberate antivirus-evasion testing of the loader code. In one documented case, the developer iteratively modified the loader to identify which code paths triggered detection, ultimately removing payload-update functionality to reduce detections while preserving deployment capability.
TwoFace is best understood as a mature post-compromise access platform for Windows-based web infrastructure rather than an initial access tool. Its operational role has included maintaining covert footholds on internet-facing servers, enabling credential collection, supporting movement across Exchange environments, and serving as a staging point for broader espionage activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
While expanding our research into the TwoFace webshell... we were able to uncover several IP addresses that logged in and directly interfaced with the shell...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Using this process, the developer was able to first determine that the cause of detection relied on the encoded and encrypted data for the embedded webshell.
TwoFace is comprised of two parts: a loader script and an embedded payload webshell... responsible for obtaining a decryption key from inbound requests, decrypting an embedded webshell and saving the decrypted webshell to the webserver.
The most important observation is the developer systematically removes lines of code until they observe a change in detection rate, specifically a decrease to locate the lines of code that are used by security vendors for detection.
The actor then issues a command that uses the “type” command to read the contents of the text file containing the passwords, followed by a command that uses “del” to delete the text file.
The first command in the logs was issued on June 18, 2016, which was a simple “whoami” command to get the username on the server.
The actor then checks the “Domain Admins” group to determine the accounts with domain administrator privileges using the following command: net group "Domain admins" /domain
284 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust binary referenced as suspicious/malicious in testing; it is noted for in-memory ELF execution and system fingerprinting behaviors.
A named post-exploitation web shell/tool mentioned only for comparison.
A web shell used to harvest credentials and linked to multiple related web-shell payloads in APT34 operations.
OilRig webshell family comprising a loader and payload architecture. HyperShell acts as a loader that decrypts and drops embedded payload webshells; HighShell is the payload webshell with multiple evolving versions and capabilities such as command execution, file browsing, upload/download, SQL interaction, network collection, and modular extensions. Minion is a closely related variant with overlapping authentication logic and modules.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.