Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence is set up based on the build (PERSIST_ENABLED=True or False). It uses four methods - TypeLib COM scriptlet hijack GhostTask-style TaskCache manipulation
The method makes it possible to create stealthy Registry keys to HKEY_CURRENT_USER (aka HKCU) without being detected by security software even in the absence of administrator access.
Persistence is set up based on the build (PERSIST_ENABLED=True or False). It uses four methods - TypeLib COM scriptlet hijack GhostTask-style TaskCache manipulation
The credential-harvesting module framework serves up a fake Windows lock screen on a compromised machine that asks the user to enter their Windows credentials in a phishing-style way, while making the prompt appear to be a normal authentication request. | Every login attempt gets collected regardless of whether it succeeds, and the victim has no indication anything is wrong. They see a standard incorrect-password prompt, try again, and eventually authenticate normally.
Those connections exit from pythonw.exe on the victim host to internal targets on ports like 445 (SMB), 3389 (RDP), 5985 (WinRM), and 1433 (MSSQL). | These credentials are then abused through the SOCKS5 tunnel to pivot to the next host using Remote Desktop Protocol (RDP) or WinRM.
The credential-harvesting module framework serves up a fake Windows lock screen on a compromised machine that asks the user to enter their Windows credentials in a phishing-style way, while making the prompt appear to be a normal authentication request. | Every login attempt gets collected regardless of whether it succeeds, and the victim has no indication anything is wrong. They see a standard incorrect-password prompt, try again, and eventually authenticate normally.
Specfically, TwinLoot uses SharePoint Online and the Microsoft Graph API for command-and-control (C2) | Specfically, TwinLoot uses SharePoint Online and the Microsoft Graph API for command-and-control (C2), Microsoft Teams’ TURN relay infrastructure for interactive access, and the victim’s own Microsoft Edge browser to disguise Graph API communications.
Tasking flows through SharePoint Online file dead-drops via the Microsoft Graph API. Interactive operator access routes through WebRTC DataChannels relayed by Microsoft Teams TURN servers.
The second channel makes use of a reverse SOCKS5 tunnel to enable interactive access and lateral movement.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based modular malware framework that operates its command-and-control through Microsoft Azure and Microsoft 365 services. It uses SharePoint Online and Microsoft Graph API for C2, Microsoft Teams TURN relay infrastructure for interactive access, and the victim's Microsoft Edge browser to blend malicious traffic with legitimate cloud activity. It harvests Windows credentials via fake lock screens, executes arbitrary commands, provides a reverse SOCKS5 pivot for lateral movement, and establishes persistence using an offline-forged mandatory profile hive technique dubbed "Corrupting the Hive Mind."
A modular Python implant framework that hides C2 inside Microsoft services. It uses SharePoint Online via Microsoft Graph API for dead-drop tasking, Microsoft Teams TURN/WebRTC for interactive access, and the victim's own headless Edge browser via CDP for transport. It supports credential harvesting through fake lock screens, reverse SOCKS5 pivoting, arbitrary command execution, persistence, reconnaissance, screenshot capture, and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.