Evil Twin — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
August 4, 2026
Last Seen
August 4, 2026

Evil Twin is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Evil Twin is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed August 4, 2026; most recent activity August 4, 2026.

Related Threat Clusters

  • 77 Counterfeit Open VSX Extensions Harvest Developer Data

    Between July 26 and August 1, 2026, 77 malicious extensions were discovered on the Open VSX marketplace, impersonating legitimate tools to harvest developer information. These 'evil twin' extensions were linked through…

    2 articles · Updated August 4, 2026

Recent Intelligence Reports

  • 77 Open VSX extensions found harvesting developer info — Bleepingcomputer · August 4, 2026

Frequently asked questions

What is Evil Twin?

Evil Twin is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Is Evil Twin still active?

The most recent intelligence report mentioning Evil Twin on ThreatCluster is dated August 4, 2026.

What is Evil Twin associated with?

Across ThreatCluster reporting, Evil Twin most frequently co-occurs with Data Breach, Open VSX, T1041 - Exfiltration Over C2 Channel, T1071 - Application Layer Protocol, T1195 - Supply Chain Compromise, among 12 tracked related entities.

What are the latest developments involving Evil Twin?

The most significant recent cluster is “77 Counterfeit Open VSX Extensions Harvest Developer Data” (2 articles · Updated August 4, 2026). Evil Twin appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on Evil Twin?

Evil Twin appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown