TWINLOOT: Python Implant Abusing Microsoft Cloud C2
Score: 9/10

TWINLOOT: Python Implant Abusing Microsoft Cloud C2

TWINLOOT is a sophisticated Python implant utilizing SharePoint for tasking, Teams TURN relays for SOCKS5 tunneling, and headless Edge for stealthy Microsoft Graph API transport.

Executive Summary

The Ontinue Cyber Defense Center identified TWINLOOT, a modular Python implant framework that operates its entire command-and-control (C2) infrastructure within trusted Microsoft cloud services. The malware employs highly advanced evasion techniques, including routing Graph API traffic through a headless instance of the victim's own Edge browser via Chrome DevTools Protocol (CDP), making C2 activity indistinguishable from legitimate user browsing.

Technically, TWINLOOT achieves persistence through a novel 'Corrupting the Hive Mind' technique, forging mandatory profile hives (NTUSER.MAN) offline to bypass registry monitoring without requiring administrative privileges. It also leverages Microsoft Teams TURN servers to establish interactive WebRTC DataChannels for lateral movement via a reverse SOCKS5 proxy. This framework demonstrates a rapid closing of the gap between academic research and active threat actor tooling, specifically adopting techniques like TURN relay abuse and blockchain-based configuration resolution.

While no direct attribution is confirmed, the campaign displays significant operational parallels with STAC4749 and Chaos group activities, particularly in its use of Teams-based social engineering (vishing) and PyArmor-protected Python payloads. The business impact is high, as the implant effectively turns compromised workstations into trusted pivot points for lateral movement while remaining largely invisible to standard identity logs and process-based network detections.

Key Details

Threat Name

TWINLOOT

Affects

—

Adversary

STAC4749 Other Adversaries and Aliases: Chaos group; DragonForce

Malware/Tools

TWINLOOT, msaRAT, Backdoor.Turn, TURNt, HOLLOWGRAPH, GRAPHBROTLI, Swarmer

Report Score

9out of 10
Quality Score
Excellent
IOC Quality10
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure10
Technical Depth9

Sources