Skip to content
TechFeedYour World Tech News

Security· August 18, 2026 at 01:00 p.m.

New Python-based Malware Framework Operates Stealthily Within Microsoft's Cloud

New Python-based Malware Framework Operates Stealthily Within Microsoft's Cloud

Key takeaways

  • The malware operates within Microsoft's cloud infrastructure
  • It uses living-off-the-land tactics for stealth
  • The modular implant is used for credential theft and persistence
  • The malware is Python-based

A new malware framework, dubbed 'TwinLoot', has been discovered that operates entirely within Microsoft's cloud infrastructure. This malware employs living-off-the-land tactics to unprecedented levels of stealth, using a modular implant for credential theft and maintaining persistence. The Python-based framework is particularly dangerous due to its ability to blend seamlessly with legitimate Microsoft processes.

Related briefings