TWINLOOT Windowless Python Implant Staging via ProgramData Marker Files

Detects execution of pythonw.exe (windowless Python) with the LAUNCHER_BG_CHILD=1 environment marker present on the command line alongside TWINLOOT-specific staging marker filenames (.agent.lock, .vendor.ok, .vendor.stamp, .reobf.manifest, client_id.txt). TWINLOOT is a modular Python implant that relaunches itself windowlessly via pythonw.exe, extracts a vendor ZIP, and uses these marker files to track staging state during its bootstrap and PyArmor-protected launcher stages, while abusing Microsoft 365/Azure services for C2.