A sophisticated cyber threat has been uncovered, operating entirely from Microsoft’s cloud infrastructure and using advanced tactics to evade detection. The malware framework, dubbed “TwinLoot,” leverages various Microsoft services to disguise its activity as legitimate cloud traffic, making it a challenging problem for security professionals.
TwinLoot uses a modular approach, employing different Microsoft services for distinct purposes. For instance, it relies on SharePoint Online and the Microsoft Graph API for command-and-control (C2), while utilizing Microsoft Teams’ TURN relay infrastructure for interactive access. Furthermore, the malware exploits the victim’s own Microsoft Edge browser to conceal its communications with the Graph API.
The researchers who discovered TwinLoot note that its activities are not entirely new, but rather a unique combination of tactics that demonstrate a high level of sophistication. The framework engages in malicious activities such as harvesting Windows credentials via fake lock screens, providing reverse SOCKS5 pivoting into victim networks, executing arbitrary commands, and creating persistent network presence through an innovative technique called “Corrupting the Hive Mind.” This method involves forging a mandatory profile hive without administrative privileges, which is the first recorded instance of its malicious use in the wild.
What sets TwinLoot apart from other cyber threats is its ability to operate entirely within Microsoft’s cloud infrastructure. The researchers discovered the malware while investigating an ongoing campaign and were able to recover its modules from under PyArmor 9.2.5 protection, decrypting the embedded configuration in the process. This level of sophistication suggests that TwinLoot may be the work of a professional or someone with extensive knowledge of both offensive tradecraft and Microsoft’s cloud architecture.
The design of TwinLoot demonstrates how a cloud productivity suite can be repurposed as an attacker’s control plane, compromising controls built around domain reputation, IP blocking, process names, and the assumption that Microsoft 365 traffic represents sanctioned user activity. Jason Soroko, senior fellow at certificate lifecycle management provider Sectigo, notes that this development requires new defensive thinking to counter the evolving threat landscape.
Two key aspects of TwinLoot’s architecture are particularly noteworthy: credential harvesting and persistence. The credential-harvesting module serves up a fake Windows lock screen on a compromised machine, prompting the user to enter their credentials in a phishing-style manner while appearing as a normal authentication request. This technique captures passwords without alerting the victim.
In conclusion, the discovery of TwinLoot highlights the need for security professionals to stay vigilant and adapt to emerging threats. The use of cloud infrastructure by cyber attackers is not new, but the sophistication and stealthiness of TwinLoot demonstrate how attackers are continually evolving their tactics. To protect themselves, users should remain cautious when interacting with Microsoft services, especially if they involve sensitive information or permissions.
As a practical takeaway for readers, it’s essential to monitor Microsoft 365 traffic closely, looking out for suspicious activity that may indicate an attacker is using the service as a command-and-control platform. Additionally, ensuring that software and services are kept up-to-date and patched can help prevent infections by malicious code like TwinLoot. By being aware of these emerging threats and taking proactive measures to secure their infrastructure, users can reduce the risk of falling victim to sophisticated cyber attacks like TwinLoot.
Source: Dark Reading — 2026-08-18