Researchers disclosed TwinLoot, a previously undocumented Python-based malware framework that conducts command-and-control almost entirely through trusted Microsoft cloud services. Ontinue said the implant uses SharePoint Online and the Microsoft Graph API as a dead-drop C2 channel, abuses Microsoft Teams TURN relay infrastructure for interactive access, and routes traffic through the victim’s own Microsoft Edge browser to blend malicious activity into normal enterprise cloud usage. Investigators linked the activity to an ongoing campaign and assessed the likely initial access vector as a Microsoft Teams social-engineering lure in which an actor posing as IT support convinced a victim to run a PowerShell command.
TwinLoot supports credential harvesting, arbitrary command execution, reconnaissance, screenshot capture, and reverse SOCKS5 tunneling for pivoting and lateral movement. Its credential theft module presents a convincing fake Windows lock screen to capture passwords, while its persistence mechanism uses an offline-forged NTUSER.MAN mandatory profile hive without requiring administrative privileges, a technique researchers described as the first recorded malicious use in the wild of this Windows internals method. Analysts said the framework’s combination of Microsoft 365 dead-drop C2, Teams relay abuse, and headless browser transport is a first-of-its-kind design, and urged defenders to baseline normal SharePoint, Teams, and Graph API activity while monitoring OAuth applications, consent grants, and other anomalous cloud behavior.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
In the TwinLoot disclosure, Ontinue reported that the malware's NTUSER.MAN-based offline registry hive persistence method represented the first recorded malicious use of that technique in the wild. The method enables persistence without administrative privileges and without typical registry modification events.
Researchers publicly disclosed TwinLoot as a malware framework that hides command-and-control inside Microsoft cloud services, including SharePoint Online, Microsoft Graph API, Teams TURN relays, and the victim's own Edge browser. Ontinue described it as the first observed framework combining Microsoft 365 dead-drop C2, Teams TURN relay abuse, and headless browser transport in a single implant.
Build-machine paths in recovered bytecode showed a developer workspace at C:\Users\Admin\LAUNCHER\... and indicated TwinLoot modules were compiled on 24 July 2026 between 18:13 and 18:15 UTC. This provides a dated glimpse into the malware's development and staging activity prior to public disclosure.
Ontinue assessed that the intrusion began with a Microsoft Teams social-engineering attack in which an actor posing as IT support convinced a victim to run a PowerShell command. That command downloaded an archive containing a Python runtime and the compiled loader payload bootstrap-fat.pyc.
While investigating an ongoing campaign in July 2026, Ontinue's Cyber Defense Center discovered the previously undocumented Python implant framework TwinLoot. During the investigation, researchers recovered PyArmor-protected modules and decrypted the malware's embedded configuration.
The domain th2ch.com was re-registered through NameCheap with privacy protection, and a Let's Encrypt certificate for sharepointx.th2ch.com was issued the same day. Ontinue later cited this infrastructure as part of the TwinLoot operator's setup.
Praetorian published research on persistence through forgotten Windows internals, covering the NTUSER.MAN-based hive technique later referenced in TwinLoot reporting as "Corrupting the Hive Mind."
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourceontinue.com
Open sourcepraetorian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.