threat-intel
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
High
Summary
TwinLoot, a sophisticated Python-based malware framework, operates entirely from within Microsoft's Azure and 365 cloud services, using various Microsoft services – SharePoint Online, Microsoft Graph API, and Teams TURN relay infrastructure – to conceal its malicious activities. The framework employs advanced living-off-the-land tactics, including a unique persistence method called ‘Corrupting the Hive Mind,’ to establish a silent and invisible presence on victim networks, and is a significant step up in complexity for attackers leveraging cloud infrastructure.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
