# Microsoft's Own Infrastructure Is Now the Attack Platform


When your firewall sees a process calling out to SharePoint, it doesn't flinch. That's precisely the problem.


Researchers at Ontinue have detailed a Python-based implant framework called TWINLOOT that routes its entire command-and-control operation through Microsoft 365 services — specifically SharePoint Online and Microsoft Teams. No sketchy domains. No suspicious IP ranges. No traffic that triggers conventional network defenses. Just your standard enterprise SaaS traffic, quietly delivering instructions to compromised machines.


This isn't a novel concept, but TWINLOOT is a particularly mature and deliberate execution of it.


## How TWINLOOT Works


The framework is modular and hardened with PyArmor — a Python obfuscation tool that makes static analysis painful. Defenders can't just grep through the source and find the C2 address because there isn't one in the traditional sense. The implant authenticates to Microsoft's legitimate infrastructure and reads its tasking from SharePoint files.


Think of it as a dead drop inside the tenant your IT team already trusts completely. Commands sit in a SharePoint document or folder. The implant polls, reads, executes. Results flow back through the same channel. From the network's perspective, this is indistinguishable from a developer syncing files or a Teams bot fetching data.


The Teams component adds another dimension: lateral movement. Teams is deeply integrated into enterprise identity — it knows your org chart, your groups, your DMs. An implant that can send and receive messages through Teams can impersonate users, spread phishing links internally, and pivot across a network in ways that external tooling can't easily see.


## The Trusted Service Exploitation Playbook


TWINLOOT belongs to a well-established but rapidly maturing category that some researchers call Living Off Trusted Services — LOTS, as opposed to the more familiar LOLBAS (Living Off the Land Binaries). The basic premise: use infrastructure your target already whitelists.


We've seen this before. BazarLoader used Google Docs for payload staging. Cobalt Strike operators have proxied C2 through Azure and AWS services. Cloudflare Workers have been weaponized for phishing redirects. Slack and Discord APIs have been abused by infostealers dropping exfiltrated data into channels. The pattern has been building for years.


What makes TWINLOOT more concerning is the depth of Microsoft 365 integration. SharePoint and Teams aren't just convenient hiding spots — they're load-bearing infrastructure for most enterprise organizations. You cannot block access to SharePoint without crippling collaboration for your entire workforce. Defenders are effectively locked out of their most natural response.


The PyArmor hardening is a meaningful secondary defense for the attacker. Python has become a popular implant language partly because it's cross-platform, partly because Python runtimes are often pre-installed or easily deployed, and partly because defenders haven't built the same mature detection coverage for Python that they have for PowerShell or compiled PE files. PyArmor on top of that makes even post-compromise analysis slower.


## What Attribution and Targeting Look Like


Ontinue characterized TWINLOOT as previously undocumented, which puts it in the category of tooling that either emerged recently or has been operating quietly long enough that incident responders haven't encountered it in public cases. Neither option is comforting.


The modular design is a tell about the operators' sophistication. Modular implants aren't built for one-off ops — they're built for repeatability, for teams, for updates. Whoever is behind TWINLOOT invested in maintainability. That's a resource investment, which points toward a threat actor with either commercial motivation or nation-state backing running persistent access campaigns rather than smash-and-grab operations.


The lateral movement capability via Teams is particularly telling. Credential theft and network traversal suggest the objective is long-term persistence and data access, not ransomware deployment. The goal appears to be intelligence — organizational, financial, or both.


## Defender Playbook


The uncomfortable reality is that traditional network-layer defenses offer limited value here. You're not going to block SharePoint. But defenders aren't helpless.


Behavioral anomaly detection on Microsoft 365 API calls matters more than ever. Most organizations have Microsoft 365 logging available through Unified Audit Logs and Defender for Cloud Apps. Baseline what normal SharePoint API access looks like for endpoints and service accounts — then alert on deviations. A machine that never touched SharePoint now polling a specific document library at regular intervals is a signal worth investigating.


Conditional Access and device compliance policies limit blast radius. An implant running on an unmanaged or compromised host should face friction when authenticating to Microsoft services. Require compliant devices, require MFA, apply risk-based Conditional Access policies that escalate authentication requirements when sign-in risk is elevated.


Hunt for PyArmor artifacts. PyArmor leaves specific runtime structures and obfuscation patterns. If your EDR or SIEM has the capability, build detection rules around PyArmor's runtime loader patterns — not to catch TWINLOOT specifically, but to flag any PyArmor-protected code executing in environments where it has no business being.


Audit Teams app permissions and service accounts. The Teams integration means attackers may have registered an app in your Azure AD tenant or compromised a service account with Teams API access. Review registered applications, their permissions, and look for anything accessing Teams programmatically that your IT team didn't provision.


---


## HackWire Analysis


TWINLOOT is notable not because it breaks new ground conceptually, but because it represents the maturation of an approach that the security industry has been slow to counter.


The "trusted service" C2 problem is structural. Every major SaaS platform — Microsoft, Google, Slack, Dropbox — offers APIs that, from a network perspective, look identical whether used legitimately or weaponized. The entire value proposition of enterprise SaaS is that it's accessible from anywhere without friction. That's also what makes it ideal attack infrastructure.


The industry has invested heavily in detecting malicious infrastructure: suspicious domains, known-bad IPs, certificate anomalies. All of that detection surface disappears when the attacker is calling graph.microsoft.com. What replaces it is behavioral detection — understanding what normal looks like and catching deviations. That requires telemetry most organizations don't have turned on, and analysis most teams don't have bandwidth for.


The Microsoft 365 ecosystem is specifically dangerous here because the attacker's "C2 server" is being paid for and maintained by Microsoft, hosted in Microsoft's datacenters, delivered over Microsoft's CDN, and trusted by every enterprise firewall on the planet. TWINLOOT operators face essentially zero infrastructure overhead and near-zero network detection risk.


This will get worse before defenders catch up. Expect to see more tooling in this category — both criminally operated and nation-state — as the techniques proliferate and PyPI makes Python implants increasingly accessible to less sophisticated actors.


The answer is Microsoft 365 telemetry treated as a security data source, not just an IT operations log. Most organizations aren't there yet.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)