Skip to content
TwinLoot Malware Exploits Microsoft Cloud for Command-and-Control Operations

TwinLoot Malware Exploits Microsoft Cloud for Command-and-Control Operations

First seen 18 Aug 2026, 13:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 19, 2026 at 13:13 UTC
  • •TwinLoot malware operates entirely within Microsoft cloud services, complicating detection.
  • •It utilizes SharePoint and Teams for command-and-control, disguising malicious traffic as legitimate.
  • •The malware can harvest credentials and maintain persistence using innovative techniques.

A new Python-based malware framework named TwinLoot has been discovered, utilizing Microsoft Azure and 365 services for its command-and-control (C2) operations. Researchers from Ontinue Cyber Defense Center identified the malware while investigating an active campaign in July 2026. TwinLoot employs various Microsoft services, including SharePoint Online for file storage and Microsoft Teams' TURN infrastructure for interactive access, effectively disguising its malicious activities as legitimate cloud traffic. The malware can harvest Windows credentials, execute arbitrary commands, and maintain persistence through innovative techniques, such as creating a forged mandatory profile hive without administrative privileges. This sophisticated approach complicates detection, as the malware's traffic appears to originate from trusted Microsoft services, making it difficult for security tools to flag it as malicious. The threat is particularly concerning due to its potential to bypass traditional security measures that rely on domain reputation and IP blocking. As of now, no specific mitigation strategies have been disclosed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-07-01
TwinLoot malware discovered
Ontinue Cyber Defense Center identified TwinLoot while investigating an active campaign, revealing its use of Microsoft services for C2 operations.
Darkreading
2026-08-18
TwinLoot report published
Researchers published findings detailing TwinLoot's sophisticated use of Microsoft Azure and 365 services for malicious activities.
Csoonline
2026-08-18
Security community alerted
The cybersecurity community has been warned about the implications of TwinLoot's operations within trusted cloud environments.
Ground.News

More articles in this cluster (9)

Following this threat?

Track TwinLoot and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed