Darkreading
TwinLoot Malware Exploits Microsoft Cloud for Command-and-Control Operations
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new Python-based malware framework named TwinLoot has been discovered, utilizing Microsoft Azure and 365 services for command-and-control (C2) operations. Researchers from Ontinue Cyber Defense Center identified the malware during an investigation of an active campaign in July 2026. TwinLoot employs various Microsoft services, including SharePoint Online and Microsoft Teams, to disguise its activities as legitimate cloud traffic. It can harvest Windows credentials, execute arbitrary commands, and maintain a persistent presence within victim networks. The malware operates without using attacker-controlled domains, making detection challenging. This sophisticated use of cloud services highlights a shift in attacker tactics, leveraging trusted platforms to evade security measures. The malware's architecture allows it to authenticate to an attacker-controlled Azure tenant, avoiding audit events in the victim's logs.
Key Points: • TwinLoot malware operates entirely within Microsoft cloud services, evading detection. • It utilizes SharePoint Online and Teams for command-and-control, disguising malicious traffic. • The malware can harvest credentials and maintain persistence without triggering security alerts.