Executive Summary
The Ontinue Cyber Defense Center has identified an advanced Python-based implant framework named TWINLOOT, active as of July 2026. This framework is highly sophisticated, operating its entire command-and-control (C2) infrastructure within trusted Microsoft services like SharePoint Online, Azure, and Microsoft Teams. By leveraging these platforms, TWINLOOT effectively hides its malicious traffic within legitimate enterprise cloud communications, bypassing standard network reputation and IP-based blocking.
Technically, the implant utilizes the Microsoft Graph API via a headless Edge browser to ferry data, and abuses Teams TURN relays to establish interactive WebRTC DataChannels for SOCKS5 pivoting. It employs a novel persistence method called "Corrupting the Hive Mind," which involves forging a mandatory profile hive (NTUSER.MAN) offline to achieve stealthy persistence without requiring administrative privileges or generating registry modification events.
While no definitive attribution is made, TWINLOOT shares significant operational overlaps with the STAC4749 cluster, which is linked to Chaos ransomware and known for Teams-based voice phishing (vishing) campaigns. The emergence of TWINLOOT represents a narrowing gap between academic offensive research and operational deployment, signaling a high level of threat to organizations relying on standard Microsoft 365 security configurations.
Key Details
Threat Name
TWINLOOT Python Implant
Affects
—
Adversary
Chaos ransomware group Other Adversaries and Aliases: STAC4749; DragonForce; Chaos group; APT41
MITRE Techniques
Malware/Tools
TWINLOOT, Backdoor.Turn, msaRAT, DragonForce, Chaos, Swarmer, HOLLOWGRAPH, GRAPHBROTLI, TURNt, sc5.exe, GRAPHRELOOK
