Executive Summary
The Ontinue Cyber Defense Center identified TWINLOOT, a modular Python implant framework that operates its entire command-and-control (C2) infrastructure within trusted Microsoft cloud services. The malware employs highly advanced evasion techniques, including routing Graph API traffic through a headless instance of the victim's own Edge browser via Chrome DevTools Protocol (CDP), making C2 activity indistinguishable from legitimate user browsing.
Technically, TWINLOOT achieves persistence through a novel 'Corrupting the Hive Mind' technique, forging mandatory profile hives (NTUSER.MAN) offline to bypass registry monitoring without requiring administrative privileges. It also leverages Microsoft Teams TURN servers to establish interactive WebRTC DataChannels for lateral movement via a reverse SOCKS5 proxy. This framework demonstrates a rapid closing of the gap between academic research and active threat actor tooling, specifically adopting techniques like TURN relay abuse and blockchain-based configuration resolution.
While no direct attribution is confirmed, the campaign displays significant operational parallels with STAC4749 and Chaos group activities, particularly in its use of Teams-based social engineering (vishing) and PyArmor-protected Python payloads. The business impact is high, as the implant effectively turns compromised workstations into trusted pivot points for lateral movement while remaining largely invisible to standard identity logs and process-based network detections.
Key Details
Threat Name
TWINLOOT
Affects
—
Adversary
STAC4749 Other Adversaries and Aliases: Chaos group; DragonForce
MITRE Techniques
Malware/Tools
TWINLOOT, msaRAT, Backdoor.Turn, TURNt, HOLLOWGRAPH, GRAPHBROTLI, Swarmer
