{"id":9171,"date":"2026-08-18T11:07:45","date_gmt":"2026-08-18T11:07:45","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9171"},"modified":"2026-08-18T11:07:45","modified_gmt":"2026-08-18T11:07:45","slug":"new-malware-turns-microsoft-cloud-into-its-control-center","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9171","title":{"rendered":"New Malware turns Microsoft cloud into its control center"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Security researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see.<\/p>\n<p class=\"wp-block-paragraph\">The Ontinue Cyber Defense Center discovered the implant while investigating an active campaign in July and has since tracked it as TWINLOOT. It was seen using SharePoint Online as a file-based dead drop, Microsoft Teams\u2019 TURN infrastructure for interactive communications, and a headless instance of the victim\u2019s own Edge browser to send Microsoft Graph API requests.<\/p>\n<p class=\"wp-block-paragraph\">Its primary C2 traffic can terminate in Microsoft IP space rather than an attacker-controlled domain, Ontinue researchers said in a <a href=\"https:\/\/www.ontinue.com\/resource\/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure\/#h-persistence-one-technique-you-should-know-about\" target=\"_blank\" rel=\"noopener\">report<\/a> shared with CSO ahead of its publication Tuesday.<\/p>\n<p class=\"wp-block-paragraph\">\u201cTWINLOOT works because defenders have been trained to treat Microsoft traffic as safe by default, and this malware was built to take full advantage of that,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/shane-barney-69026528\/\" target=\"_blank\" rel=\"noopener\">Shane Barney<\/a>, chief information security officer at Keeper Security. \u201cThere is no attacker-owned domain in the chain, which means the traffic looks exactly like what it is supposed to look like, and most detection tools will leave it alone.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Microsoft did not immediately respond to CSO\u2019s request for comment.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Malware lives inside the trust boundary<\/h2>\n<p class=\"wp-block-paragraph\">TWINLOOT\u2019s architecture separates routine tasking from \u201cinteractive\u201d access. Its SharePoint channel polls a drive roughly every 15 seconds for commands, returning results and exfiltrating stolen credentials and reconnaissance data.<\/p>\n<p class=\"wp-block-paragraph\">According to Ontinue, the implant authenticates to an attacker-controlled Azure tenant rather than the victim\u2019s Microsoft 365 environment, producing no authentication or audit events in the victim\u2019s <a href=\"https:\/\/www.csoonline.com\/article\/4163708\/microsoft-patched-an-agent-only-role-that-was-not.html\">Entra ID<\/a> logs.<\/p>\n<p class=\"wp-block-paragraph\">For interactive access, the malware can establish a reverse SOCKS5 <a href=\"https:\/\/www.csoonline.com\/article\/3804506\/millions-of-tunneling-hosts-are-vulnerable-to-spoofing-ddos-attacks-say-researchers.html\">tunnel<\/a> and route it through Microsoft\u2019s Teams TURN infrastructure. The operator can then use the compromised endpoint to access the internal network, with connections to services such as SMB, RDP, and WinRM appearing to originate from the victim machine.<\/p>\n<p class=\"wp-block-paragraph\">TWINLOOT is only the second observed case of in-the-wild Teams TURN abuse, and Ontinue says it is the first to use actual WebRTC DataChannels for the technique.<\/p>\n<p class=\"wp-block-paragraph\">The pathway is different from Edge transport. The implant launches Microsoft Edge in headless mode, attaches through the Chrome DevTools Protocol, and issues Graph API calls as \u201csame-origin fetch ()\u201d requests from within the browser. From network telemetry, it looks like a legitimate Edge process communicating with Microsoft, the researchers said.<\/p>\n<p class=\"wp-block-paragraph\">Commenting on the detection complications TWINLOOT adds, <a href=\"https:\/\/www.linkedin.com\/in\/robert-coles-5218053\/\">Robert Coles<\/a>, senior manager of threat intelligence security at Black Duck, said, \u201cAttackers are increasingly hiding inside trusted cloud services rather than using attacker-controlled infrastructure.\u201d He recommended focusing on behavioral detection, identity monitoring, and anomaly detection, including unusual Graph API activity, OAuth applications and consent grants, and anomalous SharePoint and Teams behavior.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Stealing credentials and persisting without admin rights<\/h2>\n<p class=\"wp-block-paragraph\">On command, TWINLOOT displays a Windows 10 or Windows 11 lock screen populated with the victim\u2019s real account information. It never validates the password. Instead, every password attempt is captured, encrypted, and sent to the SharePoint C2 channel. The victim receives a normal-looking incorrect password message before eventually authenticating the login.<\/p>\n<p class=\"wp-block-paragraph\">The stolen credentials can enable lateral movement through the reverse SOCKS tunnel, potentially allowing RDP, SMB, or WinRM access to other systems.<\/p>\n<p class=\"wp-block-paragraph\">The implant also contains a persistence technique that Ontinue calls \u201cCorrupting the Hive Mind.\u201d It creates a Windows \u201cNTUSER.MAN\u201d mandatory-profile hive offline, requiring no administrator privileges and generating no registry modification event.<\/p>\n<p class=\"wp-block-paragraph\">This is the first time the technique is ever used in the wild, Ontinue said. Defenders were advised to focus on anomalous <a href=\"https:\/\/www.csoonline.com\/article\/4197775\/cisa-urges-immediate-sharepoint-hardening-as-exploits-mount.html\">SharePoint<\/a>, Teams, and Graph activity rather than malware signatures alone. Ontinue also recommended disabling Edge headless mode, monitoring unusual Python activity, resetting exposed credentials, and using phishing-resistant authentication.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Security researchers are warning of a newly uncovered Python malware framework that routes much of its command-and-control (C2) activity through Microsoft services that defenders already expect to see. The Ontinue Cyber Defense Center discovered the implant while investigating an active campaign in July and has since tracked it as TWINLOOT. It was seen using SharePoint [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9172,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9171","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9171"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9171"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9171\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9172"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9171"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}