Security· August 18, 2026 at 01:00 p.m.
New Python-based Malware Framework Operates Stealthily Within Microsoft's Cloud
Key takeaways
- The malware operates within Microsoft's cloud infrastructure
- It uses living-off-the-land tactics for stealth
- The modular implant is used for credential theft and persistence
- The malware is Python-based
A new malware framework, dubbed 'TwinLoot', has been discovered that operates entirely within Microsoft's cloud infrastructure. This malware employs living-off-the-land tactics to unprecedented levels of stealth, using a modular implant for credential theft and maintaining persistence. The Python-based framework is particularly dangerous due to its ability to blend seamlessly with legitimate Microsoft processes.