Lily
Anne

TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally

Lily Anne

Sep 1, 2026

4 min read

TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally

TL;DR

TWINLOOT turns trusted Microsoft 365 services into covert attack infrastructure, combining cloud-based C2 with credential theft, persistence, and internal network pivoting.

  • The implant abuses SharePoint, Microsoft Graph, Teams TURN relays, headless Edge, and PowerShell-driven delivery to hide malicious activity inside legitimate services.
  • Defenders need Microsoft 365 security monitoring and endpoint security together to identify the processes, persistence, credential theft, and lateral movement behind trusted traffic.
  • Hexnode XDR can support endpoint investigation and containment, while Hexnode UEM adds preventive controls such as update management, compliance policies, and security configurations.

TWINLOOT shows how attackers can turn familiar Microsoft services into components of a covert attack framework. The Python implant uses SharePoint Online, Microsoft Graph, Teams infrastructure and Edge browser automation to conceal command-and-control activity.

This Microsoft Graph malware does more than hide communications. It can capture Windows credentials, execute commands, maintain persistence and provide access to internal services. The campaign reinforces a difficult reality for defenders: trusted cloud traffic can carry malicious activity from a compromised endpoint.

Stop Trusted Cloud C2 Abuse with Hexnode

How Does TWINLOOT Compromise an Endpoint?

Ontinue discovered TWINLOOT while investigating an ongoing campaign in July 2026. Researchers assessed the initial access method as Microsoft Teams social engineering.

An attacker impersonated IT support and persuaded a user to execute a PowerShell command. The command downloaded an archive containing a Python runtime and a compiled payload that loaded the implant.

This delivery method allows the attacker to bypass technical controls by exploiting the user’s trust in an internal support interaction. It also makes PowerShell malware detection critical, even when the command originates from an apparently legitimate conversation.

How TWINLOOT Abuses Microsoft Graph and Teams

TWINLOOT operates multiple command-and-control channels through Microsoft services. It uses SharePoint Online file dead drops for tasking through the Microsoft Graph API. The implant polls an attacker-controlled SharePoint drive, retrieves commands and returns collected data.

Instead of connecting directly to Microsoft Graph, TWINLOOT launches the victim’s Edge browser in headless mode. It controls the browser through the Chrome DevTools Protocol and uses it to communicate with Graph. This approach makes malicious traffic harder to separate from expected browser and Microsoft 365 activity.

The implant also establishes a reverse SOCKS5 tunnel. Operators can route the tunnel directly to their infrastructure or through Microsoft Teams TURN relays using WebRTC DataChannels. The compromised endpoint then acts as a gateway into the internal network.

Attackers can use this connection to reach services such as:

  • SMB on port 445
  • RDP on port 3389
  • WinRM on ports 5985 and 5986
  • MSSQL on port 1433

To obtain credentials, TWINLOOT displays a realistic fake Windows lock screen. It captures the entered password, encrypts it and uploads it through the SharePoint channel. Operators can then use those credentials to access other systems through the SOCKS5 tunnel.

cybersecurity-kit

Cybersecurity kit

Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.

Download the Resource Kit

Why TWINLOOT Challenges Microsoft 365 Security

TWINLOOT combines trusted SaaS infrastructure with malicious endpoint behavior. A network tool that only checks destination reputation may see Edge, SharePoint and Teams traffic instead of an obvious command-and-control server.

However, the endpoint still exposes behavioral signals. Defenders may observe unexpected PowerShell activity, pythonw.exe running from writable directories, headless Edge sessions, unusual persistence changes and connections from Python processes to internal services.

Microsoft 365 security monitoring should therefore complement endpoint security. Teams and SharePoint audit data can provide cloud context, while endpoint telemetry reveals the processes generating the activity.

How Hexnode Can Support TWINLOOT Investigation and Response

Hexnode XDR can help security teams investigate suspicious endpoint processes and events associated with an intrusion. Its centralized threat and incident views provide context about endpoint activity and health. Defenders can also use investigation queries to search endpoint data for suspicious processes and related events.

When analysts confirm malicious activity, Hexnode XDR provides response actions to isolate an affected device, kill a malicious process or quarantine a file. These actions can help contain the compromised endpoint while the security team investigates exposed credentials and lateral movement.

Hexnode UEM adds preventive controls through Windows update management, application compliance policies and security configurations. Organizations can also integrate Hexnode with Microsoft Entra Conditional Access to apply access decisions based on device compliance.

These capabilities should form part of a broader response workflow. Security teams should also review Microsoft 365 audit logs, revoke suspicious sessions, reset exposed passwords and investigate every internal system accessed through the compromised host.

Stop Trusted Services From Becoming Attack Infrastructure

TWINLOOT demonstrates that trusted Microsoft services do not guarantee trusted activity. Attackers can combine social engineering, PowerShell execution, browser automation and cloud infrastructure to build a complete intrusion path.

Enterprises need coordinated Microsoft 365 security, identity monitoring and endpoint security. This combined visibility helps teams identify the malicious process behind trusted traffic and stop one compromised endpoint from becoming a gateway across the network.

Share

Lily Anne

Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.