Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
BLUF
TwinLoot leverages trusted Microsoft cloud services to bypass security controls and exfiltrate credentials silently.
NEWS
This Python-based framework operates entirely from within Microsoft's cloud environment, utilizing legitimate tools for command and control. The malware establishes persistence and steals credentials while mimicking normal administrative traffic to avoid detection.
Why I Care
Attackers exploiting trusted vendor infrastructure make detection significantly harder for security teams monitoring network traffic. Organizations using Azure or Office 365 face heightened risks of identity compromise and prolonged unauthorized access without triggering standard alerts.
Next Steps
Security teams must audit cloud activity logs for suspicious Python execution and review identity permissions immediately. Enable advanced threat protection for cloud identities and enforce strict conditional access policies within the next seven days.
Source: Dark Reading ·