TWINLOOT Framework Abuses Microsoft Cloud Services
Score: 9/10

TWINLOOT Framework Abuses Microsoft Cloud Services

TWINLOOT is a modular Python implant using Microsoft SharePoint, Teams, and headless Edge browsers for stealthy command-and-control and lateral movement.

Executive Summary

The Ontinue Cyber Defense Center has identified an advanced Python-based implant framework named TWINLOOT, active as of July 2026. This framework is highly sophisticated, operating its entire command-and-control (C2) infrastructure within trusted Microsoft services like SharePoint Online, Azure, and Microsoft Teams. By leveraging these platforms, TWINLOOT effectively hides its malicious traffic within legitimate enterprise cloud communications, bypassing standard network reputation and IP-based blocking.

Technically, the implant utilizes the Microsoft Graph API via a headless Edge browser to ferry data, and abuses Teams TURN relays to establish interactive WebRTC DataChannels for SOCKS5 pivoting. It employs a novel persistence method called "Corrupting the Hive Mind," which involves forging a mandatory profile hive (NTUSER.MAN) offline to achieve stealthy persistence without requiring administrative privileges or generating registry modification events.

While no definitive attribution is made, TWINLOOT shares significant operational overlaps with the STAC4749 cluster, which is linked to Chaos ransomware and known for Teams-based voice phishing (vishing) campaigns. The emergence of TWINLOOT represents a narrowing gap between academic offensive research and operational deployment, signaling a high level of threat to organizations relying on standard Microsoft 365 security configurations.

Key Details

Threat Name

TWINLOOT Python Implant

Affects

—

Adversary

Chaos ransomware group Other Adversaries and Aliases: STAC4749; DragonForce; Chaos group; APT41

Malware/Tools

TWINLOOT, Backdoor.Turn, msaRAT, DragonForce, Chaos, Swarmer, HOLLOWGRAPH, GRAPHBROTLI, TURNt, sc5.exe, GRAPHRELOOK

Report Score

9out of 10
Quality Score
Excellent
IOC Quality6
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure10
Technical Depth9

Sources