Threat Intelligence

New 'TwinLoot' Malware Hides Inside Microsoft's Own Cloud Services

Dark Reading · 18 Aug 2026
Key Takeaway Don't assume traffic to trusted cloud platforms like Microsoft 365 is automatically safe—monitor for unusual account activity and credential misuse, not just suspicious external connections.

Security researchers have identified a stealthy new malware framework, dubbed TwinLoot, that takes an unusual approach to avoiding detection: it operates entirely from within Microsoft's cloud environment. By using legitimate cloud services rather than external servers, the malware blends in with normal business traffic, making it far harder for traditional security tools to spot.

TwinLoot is a modular, Python-based implant designed to steal login credentials and maintain long-term access to compromised systems. This 'living-off-the-land' technique, where attackers rely on trusted platforms and tools instead of obviously malicious infrastructure, is becoming increasingly popular because it helps threats slip past conventional defences that look for suspicious external connections.

For small and medium businesses that rely heavily on Microsoft 365 or Azure, this type of threat is particularly concerning. Many SMBs assume that traffic to and from well-known cloud providers is inherently safe, but attackers are exploiting exactly that assumption. As cybercriminals continue refining these stealth tactics, businesses need to look beyond simple 'trusted vs untrusted' traffic models.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.