CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4594

As cited

Copy frozen at (site build).

threat intel

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

A Python-based malware framework named TwinLoot operates entirely within Microsoft's cloud infrastructure using living-off-the-land techniques. The modular implant steals credentials and maintains persistence on compromised systems while evading traditional detection.

Why it matters: Organizations using Microsoft cloud services face risk from malware that leverages legitimate cloud tools and infrastructure; security teams should monitor for unusual credential activity and persistence mechanisms within their Microsoft environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

A Python-based malware framework named TwinLoot operates entirely within Microsoft's cloud infrastructure using living-off-the-land techniques. The modular implant steals credentials and maintains persistence on compromised systems while evading traditional detection.

Why it matters: Organizations using Microsoft cloud services face risk from malware that leverages legitimate cloud tools and infrastructure; security teams should monitor for unusual credential activity and persistence mechanisms within their Microsoft environments.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary