TWIZT is a financially motivated cybercriminal operator associated with a broader crimeware ecosystem centered on the Needle platform. The actor handle TWIZT is embedded in a file-harvesting payload, linking the operator to a campaign that combined Phorpiex-based malware delivery, credential-enabled spam operations, cryptomining, and cryptocurrency theft. The operation appears to be vertically integrated, with infrastructure supporting payload hosting, a live administrative panel, backend databases, spam coordination, and a private Monero mining pool. Needle functions as a crimeware-as-a-service platform with modular capabilities spanning browser and desktop cryptocurrency wallet spoofing, credential theft, cookie theft, token theft, form grabbing, clipboard hijacking, wallet file theft, browser data collection, FTP credential theft, Telegram session theft, screenshots, and system information collection. It also includes builder and launcher components that allow customized payload generation and operator management, with Telegram-integrated notifications for operational events and theft activity. Administrative elements support both English and Russian, indicating Russian-language operator usage. Campaign activity attributed to TWIZT included deployment of a file harvester that enumerated logical drives, recursively traversed files, queried installed software locations, and exfiltrated collected data. Additional components supported stealthy Monero mining with persistence, as well as spam modules that used harvested email credentials to send sextortion messages through victims' own SMTP accounts. The infrastructure showed signs of active operator monitoring and operational security, including rapid removal of hosted payloads and wiping of supporting servers after outside access. Overall, TWIZT is best characterized as a cybercriminal actor tied to a multi-function malware and fraud ecosystem focused on credential theft, cryptocurrency theft, spam abuse, data collection, and monetization through both direct theft and illicit mining.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.