TWINLOOT is a modular Python implant framework for Windows that conceals command-and-control activity inside trusted Microsoft cloud services and the victim’s own browser processes. It was observed in intrusions that began with Microsoft Teams social engineering in which an actor impersonating IT support persuaded a user to run a PowerShell command that delivered an archive containing an embedded Python runtime and a protected loader.
The framework uses SharePoint Online via the Microsoft Graph API as an always-on dead-drop channel for tasking and data exchange, polling frequently for commands and returning results through the same cloud workflow. To reduce detection, it launches Microsoft Edge in headless mode and drives it through the Chrome DevTools Protocol so Graph requests appear to originate from the browser rather than directly from the Python process. TWINLOOT also supports an interactive reverse SOCKS5 tunnel for operator access and pivoting, with traffic carried either over direct encrypted WebSocket transport or concealed through Microsoft Teams TURN relay infrastructure using WebRTC DataChannels.
TWINLOOT supports arbitrary shell command execution, system reconnaissance, screenshot capture, configuration refresh from cloud-hosted storage, and lateral movement by proxying traffic from the compromised host to internal administrative services. It includes a credential-theft module that presents a highly convincing fake Windows lock screen, captures password attempts, encrypts them, and uploads them to attacker-controlled cloud storage. Stolen credentials can then be used for follow-on access to additional systems.
The implant is hardened with PyArmor and was reported with multiple persistence options, including TypeLib COM scriptlet hijacking, GhostTask-style scheduled task cache manipulation, self-update logic, and an offline-forged NTUSER.MAN mandatory-profile hive technique that does not require administrator privileges and avoids normal live registry modification telemetry. An EtherHiding-style blockchain configuration mechanism was present but inactive in the analyzed build. Public reporting noted operational similarities to activity associated with STAC4749, DragonForce, and Chaos-group tooling, but no definitive attribution to a known threat actor was established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services."
38 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware uses multiple methods for persistence, including TypeLib COM scriplet hijacking and TaskCache manipulation
The full command set for TWINLOOT also includes system reconnaissance, screenshot capabilities, configuration loading, polling interval adjustment and arbitrary shell command execution.
un utilisateur d’exécuter une commande PowerShell téléchargeant une archive contenant un runtime Python 3.12.9 embarqué
un runtime Python 3.12.9 embarqué et un payload compilé de 39 Mo ( bootstrap-fat.pyc )
PyArmor 9.2.5 Pro ... protège ~120 modules ; 115 ont été déchiffrés statiquement
l’implant lance le navigateur Edge de la victime en mode headless ... Le trafic C2 apparaît comme msedge.exe communiquant avec Microsoft
To facilitate lateral movement, the malware collects credentials by displaying a “pixel-faithful” fake Windows lock screen upon receiving a command called “credz_waiting.” | The fake lock screen collects the victim’s password twice – always displaying an error screen after the first attempt and performing no validation on either attempt – and the user’s inputs are uploaded to the SharePoint dead drop.
The password is then sent back through the SOCKS5 tunnel and used to establish Remote Desktop Protocol (RDP), Server Message Block (SMB) and Windows Remote Management (WinRM) connections to other hosts on the local network that the victim can reach.
TTP # ... T1021.001 — Remote Services: Remote Desktop Protocol
To facilitate lateral movement, the malware collects credentials by displaying a “pixel-faithful” fake Windows lock screen upon receiving a command called “credz_waiting.” | The fake lock screen collects the victim’s password twice – always displaying an error screen after the first attempt and performing no validation on either attempt – and the user’s inputs are uploaded to the SharePoint dead drop.
Specfically, TwinLoot uses SharePoint Online and the Microsoft Graph API for command-and-control (C2) | Specfically, TwinLoot uses SharePoint Online and the Microsoft Graph API for command-and-control (C2), Microsoft Teams’ TURN relay infrastructure for interactive access, and the victim’s own Microsoft Edge browser to disguise Graph API communications.
l’implant s’authentifie sur le tenant Azure de l’attaquant et interroge un drive SharePoint toutes les 15 secondes via la Microsoft Graph API
The result: an interactive SOCKS5 proxy that exits from the victim’s own process into their internal network, turning a single compromised endpoint into a pivot point for lateral movement.
Canal interactif (reverse SOCKS5) : tunnel sur TLS/WebSocket direct ... ou via les relais TURN de Microsoft Teams
The reverse SOCKS5 tunnel is the interactive access channel. It runs over either a direct TLS/WebSocket connection to the attacker’s server or through the Teams TURN WebRTC relay.
ou via les relais TURN de Microsoft Teams ... en utilisant des WebRTC DataChannels
The first is an “always-on tasking channel” that uses a SharePoint “dead-drop” that is polled every 15 seconds for commands.
Canal de tasking (SharePoint dead-drop) ... interroge un drive SharePoint toutes les 15 secondes via la Microsoft Graph API
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python implant/backdoor framework using Microsoft 365/Azure for C2, with SharePoint dead-drop tasking via Microsoft Graph API and an interactive reverse SOCKS5 channel over TLS/WebSocket or Teams TURN/WebRTC. It uses Edge headless plus CDP for Graph traffic blending, supports multiple persistence mechanisms, and includes credential theft via a fake Windows lock screen.
A Python-based implant/backdoor that hides C2 traffic inside legitimate Microsoft services including SharePoint, Microsoft Graph, Edge, and Teams TURN infrastructure. It supports an always-on tasking channel via a SharePoint dead-drop, a reverse SOCKS5 tunnel for interactive access and lateral movement, credential harvesting through fake Windows lock screens, reconnaissance, screenshots, shell command execution, and persistence including COM scriplet hijacking, TaskCache manipulation, and a mandatory-profile hive technique.
A Python-based modular malware framework that operates its command-and-control through Microsoft Azure and Microsoft 365 services. It uses SharePoint Online and Microsoft Graph API for C2, Microsoft Teams TURN relay infrastructure for interactive access, and the victim's Microsoft Edge browser to blend malicious traffic with legitimate cloud activity. It harvests Windows credentials via fake lock screens, executes arbitrary commands, provides a reverse SOCKS5 pivot for lateral movement, and establishes persistence using an offline-forged mandatory profile hive technique dubbed "Corrupting the Hive Mind."
A modular Python implant framework that hides C2 inside Microsoft services. It uses SharePoint Online via Microsoft Graph API for dead-drop tasking, Microsoft Teams TURN/WebRTC for interactive access, and the victim's own headless Edge browser via CDP for transport. It supports credential harvesting through fake lock screens, reverse SOCKS5 pivoting, arbitrary command execution, persistence, reconnaissance, screenshot capture, and data exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.