New Malware turns Microsoft cloud into its control center

Summary

A newly discovered Python malware framework named TWINLOOT leverages Microsoft 365 services for its command-and-control (C2) infrastructure. It utilizes SharePoint Online for dead drops, Microsoft Teams for communication, and a headless Edge browser for API requests, making its traffic appear legitimate to defenders. This approach bypasses traditional detection methods by operating within the trusted Microsoft ecosystem.

IFF Assessment

FOE

This malware is bad news for defenders because it cleverly abuses trusted Microsoft cloud services for its command and control, making it very difficult to detect.

Defender Context

Defenders need to be aware of malware that blends into trusted cloud environments like Microsoft 365. Monitoring unusual API calls, traffic patterns within Teams, and unexpected SharePoint activity could be key indicators. Organizations should also review their Entra ID logs for anomalies, even though this specific malware tries to avoid them.

Read Full Story →