New malware found TWINLOOT
A new malware has been detected. TWINLOOT has used Microsoft's cloud as a command center.
According to a report by the website CSO Online, a campaign of malware types, frameworks, and system backdoors, or backdoors, called TWINLOOT, was detected by a research team from the Ontinue Cyber Defense Center in July. This malware has an interesting model: Microsoft's cloud services are used as the infrastructure of malware.
SharePoint is used as a File-Based Dead Drop. This point is a stop for sending commands from the control server (C2 or Command and Control) and an Exfiltration from the victim's machine to bypass detection and girl to the C2 server.
Microsoft Teams' TURN infrastructure is used as a communication channel between the C2 server and the malware itself to bypass traffic detection.
Headless Edge Browser and Microsoft Graph API. By malware, Edge's headless web browser is used to use the Microsoft Graph API to send requests back to the malware C2 server.
When the research team conducted an in-depth analysis, it was discovered that the architecture of TWINLOOT malware was well designed by separating common and interactive channels, such as
Routine Channel The malware will be contacted with SharePoint every 15 seconds to determine if a new command is sent from the control server, ready to send stolen code data and Reconnaissance data back to the server. In addition, the malware has also been directly connected to the hacker's Azure Tenant to avoid being detected through the Log on the victim system's Entra ID.
Interactive Channels The malware operates a Reverse SOCKS5 Tunnel via TURN, allowing hackers to use an Endpoint device to further distribute the malware in the system (Lateral Movement) with connections to internal services such as SMB, RDP, and WinRM.
In addition to the above capabilities, the malware uses a fake Windows 10 and 11 lock screen with victim information to trick the victim into entering the password. This screen does not confirm the authenticity of the password (Password Validation), but it stores data on every password input to send to SharePoint. Prepare to forward the data back to the C2 server. Not only has the malware also used the technique of creating persistence on the system (s) using the "Corrupting the Hive Mind" technique through the creation of a Mandatory Hive file of a Windows profile called " NTUSER.MAN "the embedding of the malware code, so when Windows loads the profile and reads it, it is sure that the malware code will be executed immediately. This does not require the Registry to be edited or any Admin or Administrator, which is a very insidious method.
The source has confirmed that inquiries have been made to Microsoft about the existence and operation of such malware on Microsoft systems as a result, but no reply has been made to Microsoft as of yet.
# Trending # lemon 8 diary # Microsoft # freedomhack # twinloop
