Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
ID: 8caaefcf-ce8c-5ec7-a7a6-8cbfba02ec32
STIX ID: report--8caaefcf-ce8c-5ec7-a7a6-8cbfba02ec32
Feed Name: Dark Reading
Researchers discovered a sophisticated Python malware framework named TwinLoot that uses Microsoft 365 and Azure services (SharePoint, Graph API, Teams TURN relay, and the victim's Edge browser) as a stealthy command-and-control and interactive access plane. TwinLoot modules enable credential harvesting via pixel-faithful fake Windows lock screens, a reverse SOCKS5 pivot for internal network access, and a novel persistence method—an offline-forged mandatory profile hive—making detection by traditional indicators difficult and prompting recommendations for behavioral and UEBA-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
