logo

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

ID: 8caaefcf-ce8c-5ec7-a7a6-8cbfba02ec32

STIX ID: report--8caaefcf-ce8c-5ec7-a7a6-8cbfba02ec32

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-08-18

Date Updated: 2026-08-19

Author: Elizabeth Montalbano

...
...

Researchers discovered a sophisticated Python malware framework named TwinLoot that uses Microsoft 365 and Azure services (SharePoint, Graph API, Teams TURN relay, and the victim's Edge browser) as a stealthy command-and-control and interactive access plane. TwinLoot modules enable credential harvesting via pixel-faithful fake Windows lock screens, a reverse SOCKS5 pivot for internal network access, and a novel persistence method—an offline-forged mandatory profile hive—making detection by traditional indicators difficult and prompting recommendations for behavioral and UEBA-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.