Darkreading TwinLoot Malware Exploits Microsoft Cloud for Command-and-Control Operations
Article Content
- •TwinLoot malware operates entirely within Microsoft cloud services, complicating detection.
- •It utilizes SharePoint and Teams for command-and-control, disguising malicious traffic as legitimate.
- •The malware can harvest credentials and maintain persistence using innovative techniques.
A new Python-based malware framework named TwinLoot has been discovered, utilizing Microsoft Azure and 365 services for its command-and-control (C2) operations. Researchers from Ontinue Cyber Defense Center identified the malware while investigating an active campaign in July 2026. TwinLoot employs various Microsoft services, including SharePoint Online for file storage and Microsoft Teams' TURN infrastructure for interactive access, effectively disguising its malicious activities as legitimate cloud traffic. The malware can harvest Windows credentials, execute arbitrary commands, and maintain persistence through innovative techniques, such as creating a forged mandatory profile hive without administrative privileges. This sophisticated approach complicates detection, as the malware's traffic appears to originate from trusted Microsoft services, making it difficult for security tools to flag it as malicious. The threat is particularly concerning due to its potential to bypass traditional security measures that rely on domain reputation and IP blocking. As of now, no specific mitigation strategies have been disclosed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track TwinLoot and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…