The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence.
August 18, 2026
A Python-based malware framework is taking the concept of living off the land (LOTL) to a whole new level by operating its entire command-and-control (C2) from inside Microsoft Azure and 365 services, researchers have found. And while it's common for attackers to use cloud infrastructure to hide activity, the framework has some unique qualities that demonstrates new sophistication — and which will require new defensive thinking.
Dubbed "TwinLoot" by the researchers at Ontinue Cyber Defense Center who discovered it, the modular framework uses various Microsoft services, each for a different purpose, thus disguising its activity as legitimate cloud traffic, according to a report published today. Specfically, TwinLoot uses SharePoint Online and the Microsoft Graph API for command-and-control (C2), Microsoft Teams' TURN relay infrastructure for interactive access, and the victim's own Microsoft Edge browser to disguise Graph API communications.
Related:Researcher Claims Control of ChatGPT Secure Sandbox






