# Microsoft's Own Cloud Is Now the Attack Surface
When security researchers at Ontinue's Cyber Defense Center found TwinLoot during a July investigation, they weren't looking at another piece of malware hiding *behind* Microsoft's infrastructure. They were looking at malware hiding *inside* it — using SharePoint, Graph API, Teams relay, and the victim's own Edge browser as operational components of the attack.
That distinction matters more than it might sound.
## Living Off the Land Just Got a Roof
The "living off the land" playbook is well-worn by now. Attackers use legitimate system tools — PowerShell, WMI, certutil — to avoid dropping binaries that would trigger endpoint detection. The approach became infamous during the Volt Typhoon campaigns, where Chinese state-backed operators spent months inside U.S. critical infrastructure using almost nothing but built-in Windows tools.
TwinLoot takes that philosophy and scales it into the cloud. The Python-based modular framework routes its entire command-and-control operation through services your IT team almost certainly whitelists by policy: SharePoint Online for C2 communications, the Microsoft Graph API for data transport, and Microsoft Teams' TURN relay infrastructure for interactive access. The victim's own Edge browser acts as a proxy to disguise Graph API traffic.
This isn't a clever trick — it's a structural shift. You cannot block SharePoint. You cannot flag Graph API calls as inherently suspicious. Your SIEM is not going to fire on Teams relay traffic. The attacker has effectively turned your productivity stack into their adversarial infrastructure, and you're paying the licensing costs.
## What TwinLoot Actually Does to You
Once inside, TwinLoot's modular architecture gives operators a flexible toolkit. The credential harvesting component deploys pixel-faithful fake lock screens — meaning the fake Windows login prompt is visually indistinguishable from the real one at the pixel level. Users type in their passwords, and TwinLoot collects them. It's not phishing via email; it's phishing the user on their own machine, in the moment they think they're authenticating normally.
Beyond credential theft, the framework establishes a reverse SOCKS5 proxy, turning compromised machines into pivot points that let attackers route traffic deeper into the victim network. Combined with arbitrary command execution, this gives operators the equivalent of a hands-on-keyboard presence without triggering the behavioral detections that many EDR products rely on.
The persistence mechanism is the most technically notable piece. Ontinue's researchers dubbed it "Corrupting the Hive Mind" — a technique involving an offline-forged mandatory profile hive that achieves persistence without requiring administrative privileges. The researchers say this is the first recorded malicious use of this method in the wild. That caveat about administrative privileges is significant: many organizations tier their endpoint hardening around the assumption that persistence requires elevation. TwinLoot is punching through that assumption.
## Why Your Tenant Logs Aren't Going to Save You
Here's the uncomfortable truth for defenders: the security controls you've invested in are largely oriented around detecting anomalies. Unusual processes, unexpected network destinations, suspicious authentication events. TwinLoot is specifically engineered to produce none of those signals.
Traffic to SharePoint Online is normal. Graph API calls are normal. TURN relay traffic from Teams is normal. The Edge browser making Graph API requests is normal — it's what Edge *does*. The framework has effectively constructed a threat that looks, from a log perspective, like a slightly busy Microsoft 365 workday.
This puts pressure on behavioral analytics that operate at a higher level of abstraction — anomaly detection on *volume* and *pattern* of Graph API calls rather than their mere presence, or user behavior analytics (UBA) catching the lock screen interaction before credentials are entered. Neither is trivial to deploy or tune.
The absence of administrative privilege requirements for the persistence technique compounds the problem. A meaningful chunk of endpoint hardening and monitoring assumes that persistent implants need elevated access. Organizations that have tiered their defenses accordingly may have a blind spot here.
## The Broader Architecture Problem
TwinLoot fits into a threat pattern that has been accelerating since late 2024: attackers treating cloud service APIs as C2 channels rather than using dedicated attacker-controlled infrastructure. Researchers have documented similar techniques using Google Drive, Slack, and Discord for command-and-control — all services where blocking traffic is operationally untenable.
What TwinLoot adds to that lineage is the depth of Microsoft service integration. It's not using one Microsoft service; it's using *multiple*, each for a distinct operational purpose, in a way that distributes the attack surface across services with different logging behaviors and different security team attention levels. SharePoint gets one kind of scrutiny. Graph API gets another. Teams relay infrastructure is rarely monitored at the content level at all.
The modular design also suggests operational maturity. This is not a commodity tool. The architecture makes it adaptable — modules can be swapped out, updated, or replaced without rebuilding the entire framework. That's an investment in longevity.
---
## HackWire Analysis
TwinLoot is being covered as a cloud-LOTL story, and that framing is accurate but incomplete. The more important signal here is what it reveals about the current state of detection parity.
The security industry has spent several years building out EDR/XDR capabilities that are genuinely effective at catching binary-based, file-system-heavy implants. Vendors have done real work on behavioral detection. That progress pushed sophisticated threat actors toward techniques that blended into the OS, then techniques that blended into the network, and now techniques that blend into the SaaS stack. TwinLoot is the logical endpoint of that adaptive pressure.
The "Corrupting the Hive Mind" persistence technique deserves more attention than it's getting in current coverage. Most reporting on TwinLoot is leading with the cloud C2 angle, which is the flashy part. But novel unprivileged persistence mechanisms are rarer and, in some ways, more consequential. If this technique proliferates into crimeware tooling — which novel persistence methods historically do, within 12-18 months of their public disclosure — organizations that have hardened only against admin-privilege persistence are going to have a gap.
For defenders with Microsoft 365 environments, the practical priority is twofold: implement Conditional Access policies that create behavioral baselines for Graph API usage per user and per application, and get ahead of the Teams relay blind spot by ensuring your network monitoring actually captures what's traversing TURN relay channels, even if you can't decrypt it. The volume patterns are detectable even when content isn't.
Security teams should also treat the fake lock screen technique as a reason to revisit user training. "Pixel-faithful" means users cannot be expected to visually identify the fake. The defense has to be process-level: users who understand they should never re-enter credentials after their screen locks unexpectedly, and who know how to escalate when that happens.
Microsoft has a harder problem. Their services are being weaponized at the API level, and they face a genuine tension between providing rich programmatic access — which is core to their enterprise value proposition — and preventing that access from being used as covert infrastructure. Expect Graph API abuse monitoring to become a more active area of Microsoft Defender investment.
— HackWire Editorial
---
## Related Coverage