New malware turns Microsoft 365 and Azure into its control center
The pathway is different from Edge transport. The implant launches Microsoft Edge in headless mode, attaches through the Chrome DevTools Protocol, and issues Graph API calls as “same-origin fetch ()” requests from within the browser.
Warning to enterprises: Vibe coding can be a threat
The pathway is different from Edge transport. The implant launches Microsoft Edge in headless mode, attaches through the Chrome DevTools Protocol, and issues Graph API calls as “same-origin fetch ()” requests from within the browser. From network telemetry, it looks like a legitimate Edge process communicating with Microsoft, the researchers said.
Commenting on the detection complications TWINLOOT adds, Robert Coles, senior manager of threat intelligence security at Black Duck, said, “Attackers are increasingly hiding inside trusted cloud services rather than using attacker-controlled infrastructure.” He recommended focusing on behavioral detection, identity monitoring, and anomaly detection, including unusual Graph API activity, OAuth applications and consent grants, and anomalous SharePoint and Teams behavior.
Stealing credentials and persisting without admin rights
On command, TWINLOOT displays a Windows 10 or Windows 11 lock screen populated with the victim’s real account information. It never validates the password. Instead, every password attempt is captured, encrypted, and sent to the SharePoint C2 channel. The victim receives a normal-looking incorrect password message before eventually authenticating the login.
