تخطي إلى المحتوى الرئيسي
Cyber News Dark Reading 3 days ago

Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud

Da
Dark Reading

A Python-based malware framework is taking the concept of living off the land (LOTL) to a whole new level by operating its entire command-and-control (C2) from inside Microsoft Azure and 365 services, researchers have found. And while it's common for attackers to use cloud infrastructure to hide activity, the framework has some unique qualities that demonstrates new sophistication — and which will require new defensive thinking.

Dubbed "TwinLoot" by the researchers at Ontinue Cyber Defense Center who discovered it, the modular framework uses various Microsoft services, each for a different purpose, thus disguising its activity as legitimate cloud traffic, according to a report published today. Specfically, TwinLoot uses SharePoint Online and the Microsoft Graph API for command-and-control (C2), Microsoft Teams' TURN relay infrastructure for interactive access, and the victim's own Microsoft Edge browser to disguise Graph API communications.

Related:Researcher Claims Control of ChatGPT Secure Sandbox

Using this foundation, TwinLoot engages in various malicious activities, including harvesting Windows credentials via pixel-faithful fake lock screens, providing a reverse SOCKS5 pivot into victim networks, executing arbitrary commands, and creating a persistent network presence in various ways, the researchers found.

The last activity is particularly unique, the researchers noted, as it "involved an offline‑forged mandatory profile hive created without administrative privileges." The researchers called the technique "Corrupting the Hive Mind," observing that it's "the first recorded malicious use of this persistence method in the wild."

Cyberattacker-Controlled Cloud Services

View Original Report

This intelligence was aggregated from Dark Reading.

Read on Source