Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Ontinue

Ontinue Vendor Cyber Rating & Cyber Score

ontinue.com

As a leading provider of AI-powered managed extended detection and response (MXDR) services, Ontinue is on a mission to be the most trusted security partner that empowers customers to embrace and accelerate digital transformation by using AI to operate more at scale, and with less risk. The combination of AI and human expertise is essential for delivering effective managed security that is tailored to a customer’s unique environment, operational constraints, and risks. Our MXDR service combines powerful proprietary AI with the industry’s first collaboration with Microsoft Teams to continuously build a deep understanding of our customers’ environments, informing how we prevent, detect, and respond to threats. Our Microsoft expertise allows


Ontinue A.I CyberSecurity Scoring

Ontinue
Company Information
Website:https://www.ontinue.com
Employees number:214
Number of followers:7,415
NAICS:541514
Industry Type:Computer and Network Security
Homepage:ontinue.com
Ontinue Risk Score (AI oriented)
Between 700 and 749
logo
OntinueComputer and Network Security
Updated:
18/08/2026
736/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Ontinue Global Score (TPRM)
xxxx
logo
OntinueComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OntinueModerate
Current Score
736Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
736Before Incident
AUGUST 2026
736Before Incident
JULY 2026
752Before Incident
Cyber Attack
01 Jul 2026Ontinue
Ontinue: TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

TWINLOOT Python Implant Framework Exploits Microsoft Services for Stealthy C2 Operations

735After Incident
LOW-17
ONT1787063426
New Python Implant Framework TWINLOOT Exploits Microsoft Services for Stealthy C2 Operations Cybersecurity researchers at Ontinue have uncovered TWINLOOT, a previously undocumented Python-based implant framework designed to conceal its command-and-control (C2) infrastructure within trusted Microsoft services. The malware, discovered during an investigation into an ongoing campaign in July 2026, leverages SharePoint Online, Microsoft Teams TURN servers, and the Microsoft Graph API to evade detection while maintaining persistent access to compromised systems. ### Key Features & Attack Chain TWINLOOT operates through two parallel C2 channels, both exploiting legitimate Microsoft services: 1. SharePoint Dead Drop C2 - Authenticates to an attacker-controlled Azure tenant and polls a SharePoint drive for commands every 15 seconds. - Uses a headless instance of the victim’s Edge browser to ferry Graph API traffic, blending malicious activity with normal network behavior. - Enables data exfiltration, arbitrary command execution, and credential harvesting via pixel-perfect fake lock screens. 2. Reverse SOCKS5 Tunnel for Interactive Access - Establishes a SOCKS5 proxy over WebRTC DataChannels, relayed through Microsoft Teams TURN servers or a direct TLS/WebSocket connection. - Allows threat actors to pivot laterally within victim networks, mimicking legitimate traffic from the compromised host to internal services (e.g., SMB, RDP, WinRM, MSSQL). ### Initial Access & Persistence The attack begins with a social engineering lure via Microsoft Teams, where the threat actor posing as IT support tricks victims into executing a PowerShell command that downloads a 39 MB compiled Python payload ("bootstrap-fat.pyc"). This loader deploys TWINLOOT, which employs four persistence mechanisms, including: - TypeLib COM scriptlet hijacking - GhostTask-style TaskCache manipulation - Self-updating via a reob.json manifest - A novel Registry-based method using Swarmer, an open-source tool that creates stealthy HKCU Registry keys without admin privileges by generating a mandatory profile hive (NTUSER.MAN) marking the first known malicious use of this technique in the wild. ### Credential Theft & Lateral Movement TWINLOOT captures Windows credentials through fake lock screen prompts triggered by the "credz_waiting" command. The entered password regardless of validity is encrypted and exfiltrated to the attacker’s SharePoint drive, then abused via the SOCKS5 tunnel for RDP or WinRM-based lateral movement. ### Evasion & Development The implant is PyArmor-hardened to resist analysis and can fall back to an EtherHiding-style mechanism (though unused in the current build) if Azure Blob Storage dead drops fail. Its modular design suggests active development, with researchers noting operational overlaps with STAC4749, a threat cluster linked to Teams voice phishing campaigns and Chaos ransomware deployments. However, TWINLOOT’s implementation differs significantly, indicating either a rebuilt toolset or a separate actor adopting similar tactics. ### Broader Trend: TURN Relay Abuse TWINLOOT joins a growing list of malware exploiting TURN (Traversal Using Relays around NAT) relays for C2 communications, a technique first publicly detailed as "Ghost Calls" in 2025. Other recent examples include: - Backdoor.Turn (June 2026): A Go-based RAT used by DragonForce ransomware, leveraging Teams TURN relays via QUIC sessions. - msaRAT (August 2026): A Rust-based RAT attributed to the Chaos ransomware group, which abuses Twilio TURN relays and Chrome DevTools Protocol (CDP) to control a headless browser for C2. Both TWINLOOT and msaRAT independently adopted headless browser-based C2 within the same month, highlighting a convergence in offensive tradecraft among disparate threat actors. The reliance on Microsoft and cloud services for C2 infrastructure underscores the challenges of detecting malicious activity within trusted enterprise environments.
INCIDENT DETAILS -
TYPE
Malware Implant Framework
MOTIVATION
Data ExfiltrationCredential HarvestingLateral MovementPersistent Access
IMPACT
CredentialsSensitive System DataWindows SystemsLateral Movement via RDP/WinRMPersistent Backdoor AccessIdentity Theft Risk: High
DATA BREACH
CredentialsSystem DataSensitivity Of Data: High
JUNE 2026
752Before Incident
MAY 2026
752Before Incident
APRIL 2026
752Before Incident
MARCH 2026
752Before Incident
FEBRUARY 2026
752Before Incident
JANUARY 2026
752Before Incident
DECEMBER 2025
752Before Incident
NOVEMBER 2025
752Before Incident
OCTOBER 2025
752Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Ontinue ?
?
What was Ontinue's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Ontinue's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Ontinue's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Ontinue ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Ontinue's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?