TwinLoot Malware Framework

 


TwinLoot 

Note: TwinLoot is newly disclosed and public IOC coverage is still limited. The most valuable detection opportunities are behavioral indicators and Microsoft 365 telemetry rather than simple IP/domain blocking.

Host-Based Indicators

Files and Components

  • Python-based implant protected with PyArmor 9.2.5.
  • Observed loader file:
    • bootstrap-fat.pyc (approximately 39 MB compiled Python payload).
  • Deployment includes a packaged Python runtime on victim systems.

Suspicious Process Activity

  • Headless Microsoft Edge instances launched for Graph API communications.
  • PowerShell launched from Teams-driven social engineering scenarios.
  • Unexpected Python processes on endpoints where Python is not normally used.

Microsoft 365 Indicators

SharePoint Activity

Look for:
  • SharePoint Online drives being polled repeatedly at short intervals (approximately every 15 seconds).
  • Suspicious file creation/modification patterns in SharePoint used as "dead-drop" command channels.
  • Access to SharePoint resources belonging to unfamiliar Azure tenants.

Graph API

Look for:
  • Frequent Graph API requests originating from Edge processes without corresponding user activity.
  • Graph traffic authenticated against attacker-controlled Azure tenants rather than your organization's tenant.

Network Indicators

Teams/WebRTC Abuse

Monitor for:
  • Unusual outbound WebRTC sessions.
  • Unexpected use of Microsoft Teams TURN relay infrastructure.
  • Reverse SOCKS5 tunneling behavior originating from endpoints.

Network Characteristics

  • Traffic terminating at legitimate Microsoft IPs rather than attacker-owned infrastructure.
  • Heavy SharePoint, Graph API, Teams, and Azure communication from endpoints that do not normally generate such activity.

Credential Theft Indicators

TwinLoot reportedly uses:
  • Pixel-perfect fake Windows lock screens.
  • Credential harvesting via lock-screen impersonation.
Investigate:
  • Unexpected lock screen events.
  • User reports of repeated authentication prompts.
  • Credential use from systems immediately after suspicious lock-screen activity.

Persistence Indicators

Researchers identified four persistence mechanisms, including a novel technique called:
"Corrupting the Hive Mind"
  • Uses a forged mandatory profile hive (NTUSER.MAN).
  • Does not require local administrator rights.
  • Described as the first observed malicious use of this technique in the wild.
Investigate:
  • Unexpected creation or modification of NTUSER.MAN.
  • Changes to user profile templates.
  • User profile hive anomalies across endpoints.

High-Priority Defensive Actions

  1. Hunt for headless Edge processes making Graph API calls.
  2. Review SharePoint audit logs for repetitive automated access.
  3. Monitor Teams TURN/WebRTC usage from workstations.
  4. Alert on Python execution from user endpoints where not expected.
  5. Review PowerShell launches originating from Teams interactions.
  6. Check for accesses authenticated to external Azure tenants.

For a Microsoft environment, I would prioritize Defender XDR Advanced Hunting and Microsoft Sentinel KQL hunts, as TwinLoot's strength is blending into legitimate Microsoft 365 traffic rather than relying on traditional malware infrastructure.

Comments

Popular posts from this blog

Entire List Leaked for Canvas Ransomware Attack

WSUS CVE-2025-59287 Mitigation

Cloud Infrastructures are Having a Bad Week

CVE-2025-58034 Fortinet Warnings and Mitigation

Broadcom is dismantling of VMware Cloud Service Providers (VCSPs)

FBI Seizes RAMP Cybercrime Forum

Instagram Data Leak Update

CodeRED emergency alert system is currently down across many regions!

Notepad++ update service was compromised

SitusAMC Breached!