Silent ‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud

Microsoft’s Cloud Services Hijacked by Stealthy ‘TwinLoot’ Malware Framework

A sinister malware framework, dubbed “TwinLoot” by its discoverers, has been found operating entirely from within Microsoft’s cloud services. This Python-based framework uses various Microsoft tools to disguise its malicious activity as legitimate traffic, making it a masterclass in stealth and sophistication.

Researchers at Ontinue Cyber Defense Center stumbled upon TwinLoot while investigating an ongoing cyber campaign in July. What they found was a modular implant that not only steals credentials but also achieves persistence on compromised systems. The framework’s design is noteworthy for its use of living-off-the-land (LOTL) tactics, which allow it to blend seamlessly into the victim’s environment.

TwinLoot’s command-and-control (C2) infrastructure resides within Microsoft Azure and 365 services, making it nearly undetectable. It utilizes SharePoint Online and the Microsoft Graph API for C2, while also leveraging Microsoft Teams’ TURN relay infrastructure for interactive access. The framework even uses the victim’s own Microsoft Edge browser to disguise communications with the Graph API.

The malware’s malicious activities are varied and insidious. It can harvest Windows credentials via fake lock screens, provide a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and create a persistent network presence in multiple ways. One particularly unique technique involves creating an offline-forged mandatory profile hive without administrative privileges – a tactic dubbed “Corrupting the Hive Mind” by the researchers.

TwinLoot’s design demonstrates a high level of sophistication, suggesting that it is the work of a professional or someone with extensive knowledge of Microsoft’s cloud architecture. The framework’s developer had set up expired domains weeks in advance and created a purpose-built Azure AD application, all within a seven-week window.

The most striking aspect of TwinLoot is its ability to disguise itself as legitimate traffic, making it challenging for security tools to detect. Its use of cloud services also weakens traditional controls built around domain reputation, IP blocking, process names, or the assumption that Microsoft 365 traffic represents sanctioned user activity.

As Jason Soroko, senior fellow at Sectigo, notes, “TwinLoot shows how a cloud productivity suite can be turned into an attacker’s control plane. This weakens controls built around…the assumption that Microsoft 365 traffic represents sanctioned user activity.”

For organizations relying on Microsoft’s cloud services, this discovery serves as a stark reminder of the importance of robust security measures. Users should be cautious when interacting with cloud-based applications and services, and administrators must stay vigilant in monitoring for suspicious activity.

In practical terms, users can take steps to mitigate TwinLoot-like threats by:

* Regularly updating software and plugins

* Implementing strict access controls and least privilege principles

* Monitoring cloud activity and suspicious traffic patterns

* Educating users about phishing and social engineering tactics

By staying informed and proactive, organizations can reduce their exposure to stealthy malware frameworks like TwinLoot.


Source: Dark Reading — 2026-08-18