New 'TwinLoot' Malware Hides Inside Microsoft's Own Cloud Services
Security researchers have identified a stealthy new malware framework, dubbed TwinLoot, that takes an unusual approach to avoiding detection: it operates entirely from within Microsoft's cloud environment. By using legitimate cloud services rather than external servers, the malware blends in with normal business traffic, making it far harder for traditional security tools to spot.
TwinLoot is a modular, Python-based implant designed to steal login credentials and maintain long-term access to compromised systems. This 'living-off-the-land' technique, where attackers rely on trusted platforms and tools instead of obviously malicious infrastructure, is becoming increasingly popular because it helps threats slip past conventional defences that look for suspicious external connections.
For small and medium businesses that rely heavily on Microsoft 365 or Azure, this type of threat is particularly concerning. Many SMBs assume that traffic to and from well-known cloud providers is inherently safe, but attackers are exploiting exactly that assumption. As cybercriminals continue refining these stealth tactics, businesses need to look beyond simple 'trusted vs untrusted' traffic models.