← Back to Feed

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

August 18, 2026 · Dark Reading · Severity: HIGH

A new Python-based malware framework called TwinLoot takes living-off-the-land tactics to new heights of stealth, operating its entire command-and-control infrastructure from within trusted Microsoft cloud services. The modular, PyArmor-hardened implant steals credentials, achieves persistence, and routes its communications through SharePoint and Microsoft Teams. Organizations using Microsoft 365 should monitor for unusual Graph API activity and credential theft attempts to detect this advanced threat.

Key Takeaways

  • TwinLoot malware framework operates entirely from Microsoft cloud infrastructure for unmatched stealth.
  • The PyArmor-hardened Python implant uses SharePoint for command dead-drops and Teams for relay communications.
  • Organizations using Microsoft 365 should monitor for unusual Graph API activity and credential theft attempts.
☕ Buy a Coffee