HackMyIP
← Back to News
2026-08-18 Dark Reading

TwinLoot Malware Hides in Microsoft Cloud to Steal Credentials

MalwareCloud SecurityThreat Intel

Security researchers have uncovered a sophisticated Python-based malware framework dubbed “TwinLoot” that operates almost entirely from within Microsoft’s cloud infrastructure, representing a significant evolution in living-off-the-land (LOTL) tradecraft. By abusing legitimate cloud services for command-and-control, payload delivery, and data exfiltration, the threat actors effectively camouflage malicious traffic among trusted Microsoft domains, making detection by conventional network defenses exceptionally difficult.

TwinLoot’s modular implant is engineered for stealth and flexibility. Written in Python, the framework leverages native Microsoft APIs and trusted cloud resources to stage additional payloads, harvest browser-stored credentials, and establish persistence on compromised endpoints. Its modular architecture allows operators to selectively deploy capabilities—ranging from credential dumping to lateral movement—without writing significant new code on the victim machine, reducing forensic artifacts and evading endpoint detection and response (EDR) solutions that monitor for known malware signatures.

The credential-stealing component is particularly concerning for enterprises, as TwinLoot targets passwords saved in browsers, email clients, and corporate SSO tokens stored in memory. Once captured, stolen credentials are transmitted back through Microsoft’s own cloud channels, blending with legitimate API traffic. Defenders are urged to audit Azure and Microsoft 365 activity logs for anomalous token usage, unused OAuth consents, and unusual sign-in patterns, while employees should verify the safety of their accounts using an email breach checker and routinely evaluate stored passwords with a password checker.

TwinLoot underscores a growing trend in which adversaries weaponize the trust placed in hyperscale cloud providers. Organizations should enforce least-privilege access controls on Microsoft cloud tenants, enable Conditional Access policies with device compliance requirements, and monitor for suspicious service principal activity. As cloud-native malware continues to blur the line between legitimate and malicious traffic, a layered defense—combining identity hardening, continuous threat intel ingestion, and proactive exposure management—remains essential. Security teams can further validate their own external attack surface by running a privacy checkup to identify misconfigurations that cloud-resident threats like TwinLoot are designed to exploit.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →