As cited
Copy frozen at (site build).
threat intel
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
A Python-based malware framework named TwinLoot operates entirely within Microsoft's cloud infrastructure using living-off-the-land techniques. The modular implant steals credentials and maintains persistence on compromised systems while evading traditional detection.
Why it matters: Organizations using Microsoft cloud services face risk from malware that leverages legitimate cloud tools and infrastructure; security teams should monitor for unusual credential activity and persistence mechanisms within their Microsoft environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
A Python-based malware framework named TwinLoot operates entirely within Microsoft's cloud infrastructure using living-off-the-land techniques. The modular implant steals credentials and maintains persistence on compromised systems while evading traditional detection.
Why it matters: Organizations using Microsoft cloud services face risk from malware that leverages legitimate cloud tools and infrastructure; security teams should monitor for unusual credential activity and persistence mechanisms within their Microsoft environments.
- Source published
- First seen by Cybersecurity Tracker