TwinLoot Malware Exploits Microsoft Cloud for Command-and-Control Operations

TwinLoot Malware Exploits Microsoft Cloud for Command-and-Control Operations

First seen 18 Aug 2026, 13:32 UTC CsoonlineDarkreadingwww.ontinue.comwww.praetorian.com 89% similarity 69.5

Article Content

Browse articles
ThreatCluster

A new Python-based malware framework named TwinLoot has been discovered, utilizing Microsoft Azure and 365 services for command-and-control (C2) operations. Researchers from Ontinue Cyber Defense Center identified the malware during an investigation of an active campaign in July 2026. TwinLoot employs various Microsoft services, including SharePoint Online and Microsoft Teams, to disguise its activities as legitimate cloud traffic. It can harvest Windows credentials, execute arbitrary commands, and maintain a persistent presence within victim networks. The malware operates without using attacker-controlled domains, making detection challenging. This sophisticated use of cloud services highlights a shift in attacker tactics, leveraging trusted platforms to evade security measures. The malware's architecture allows it to authenticate to an attacker-controlled Azure tenant, avoiding audit events in the victim's logs.

Key Points: • TwinLoot malware operates entirely within Microsoft cloud services, evading detection. • It utilizes SharePoint Online and Teams for command-and-control, disguising malicious traffic. • The malware can harvest credentials and maintain persistence without triggering security alerts.

ThreatCluster AI How this analysis works

Timeline

2026-07-01
TwinLoot malware discovered
Researchers identified TwinLoot while investigating an active cyber campaign, revealing its sophisticated use of Microsoft services.
Darkreading
2026-08-18
Research report published
Ontinue Cyber Defense Center published findings on TwinLoot, detailing its operation and threat level.
Csoonline

Community

Browse all →