Back Darkreading Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence.
A Python-based malware framework is taking the concept of living off the land (LOTL) to a whole new level by operating its entire command-and-control (C2) from inside Microsoft Azure and 365 services, researchers have found. And while it's common for attackers to use cloud infrastructure to hide activity, the framework has some unique qualities that demonstrates new sophistication — and which will require new defensive thinking.
Dubbed "TwinLoot" by the researchers at Ontinue Cyber Defense Center who discovered it, the modular framework uses various Microsoft services, each for a different purpose, thus disguising its activity as legitimate cloud traffic, according to a report published today. Specfically, TwinLoot uses SharePoint Online and the Microsoft Graph API for command-and-control (C2), Microsoft Teams’ TURN relay infrastructure for interactive access, and the victim’s own Microsoft Edge browser to disguise Graph API communications.
Using this foundation, TwinLoot engages in various malicious activities , including harvesting Windows credentials via pixel-faithful fake lock screens, providing a reverse SOCKS5 pivot into victim networks, executing arbitrary commands, and creating a persistent network presence in various ways, the researchers found.
The last activity is particularly unique, the researchers noted, as it "involved an offline‑forged mandatory profile hive created without administrative privileges," according to the report. They The researchers called the technique "Corrupting the Hive Mind," observing that it's "the first recorded malicious use of this persistence method in the wild."
The researchers discovered TwinLoot while investigating an ongoing campaign in July, recovering the malware's modules from under PyArmor 9.2.5 protection and decrypting the embedded configuration, according to the report.
While most of TwinLoot's individual LOTL tactics they observed are not new — SharePoint already has been used as a C2 dead-drop, for instance — their combination into a single operational implant is. "TwinLoot is the first we have seen to combine Microsoft 365 dead-drop C2, Teams TURN relay abuse , and headless browser transport within a single framework," according to Ontinue.
"TwinLoot shows how a cloud productivity suite can be turned into an attacker’s control plane," observes Jason Soroko, senior fellow at certificate lifecycle management provider Sectigo. "This weakens controls built around domain reputation, IP blocking, process names, or the assumption that Microsoft 365 traffic represents sanctioned user activity."
Indeed, its design demonstrates that TwinLoot is likely the work of a professional, or at least "someone who understood both offensive tradecraft and Microsoft’s cloud architecture," according to the report.
"The developer had staged two expired domains weeks in advance, registered a purpose-built Azure AD application, stood up a SharePoint site as a dead-drop, and ported a cutting-edge conference tool into a production Python implant, all within a seven-week window," according to the report. The result of this work is an interactive SOCKS5 proxy that exits from the victim’s own process into their internal network, therefore turning a single compromised endpoint into a pivot point for lateral movement.
Two aspects of TwinLoot's architecture — credential harvesting and the aforementioned persistence — are especially notable for their structure and how invisible they appear to the victim.
The credential-harvesting module framework serves up a fake Windows lock screen on a compromised machine that asks the user to enter their Windows credentials in a phishing-style way, while making the prompt appear to be a normal authentication request. It then captures the passwords without the user knowing anything is amiss.
"Every login attempt gets collected regardless of whether it succeeds, and the victim has no indication anything is wrong," Shane Barney, CISO at cybersecurity firm Keeper Security, observes. "They see a standard incorrect-password prompt, try again, and eventually authenticate normally."
Meanwhile, the " Corrupting the Hive Mind" persistence technique "is just as quiet," he says. It does this by building a mandatory profile hive offline using legitimate Windows APIs, with no registry modification events or elevation required. "This means that standard detection logic will not surface it," he says.
Indeed, the real operational challenge that TwinLoot creates is making attacker traffic "genuinely indistinguishable from a normal user's activity," Barney says. So what should defenders do when an entire malware framework uses advanced LOLT to create the illusion of normalcy? He suggests mapping traffic trends for each service.
"Security teams need to know what normal looks like for every account touching SharePoint, Teams, and Graph API integrations, and they need to be alerting on deviation from that baseline," Barney says. "That shift from detecting bad actions to detecting differences is what this class of attack demands."
Indeed, behavioral detection is the way forward for organizations to defend against sophisticated LOLT as attackers continue to evolve their tacics. "As threat actors increasingly abuse legitimate cloud services, spotting what's unusual becomes more important than simply blocking what's known to be bad," he observes.
Meanwhile, "security teams should prioritize monitoring unusual Microsoft Graph API activity, auditing OAuth applications, and consent grants, investigating anomalous SharePoint and Teams activity, detecting browser automation and abuse of legitimate processes, and correlating identity, endpoint, and cloud telemetry," says Robert Coles, senior manager of threat intelligence security at security firm Black Duck.
They should also invest in behavioral analytics and user/entity behavior analytics (UEBA) capabilities while expanding detections beyond traditional indicators such as registry modifications or administrative actions, he adds.
Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician.
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
What Every Enterprise Should Know Securing Cloud Assets In the Age of AI
The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember
Building a Secure AI Strategy for the Enterprise
Is your AppSec program Mythos Ready?
Experts Explain How to Develop a Framework for Cyber-Fraud Fusion
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
