New Malware turns Microsoft cloud into its control center

Chronological Source Flow
Back

AI Fusion Summary

The Ontinue Cyber Defense Center has identified TWINLOOT, a new Python malware framework that leverages Microsoft services for command-and-control activity. This implant utilizes SharePoint Online as a file-based dead drop and Microsoft Teams’ TURN infrastructure for interactive communications. Additionally, it employs a headless Edge browser to send Microsoft Graph API requests. By routing primary C2 traffic through Microsoft IP space instead of attacker-controlled domains, the malware effectively blends in with expected network traffic to evade defenders.
Community Comments
Loading updates...
0