Back to Feed
MalwareAug 18, 2026

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

New 'TwinLoot' malware uses Microsoft cloud for stealthy credential theft and persistence.

Summary

A new malware framework named 'TwinLoot' has been discovered, leveraging Microsoft's cloud infrastructure to operate with extreme stealth. This Python-based malware employs living-off-the-land tactics, using a modular implant to steal credentials and establish persistence on compromised systems, making it difficult to detect.

Entities

Microsoft (vendor)cloud (technology)