#8
The Hacker News
general
August 18, 2026 at 12:38 UTC
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
By [email protected] (The Hacker News)
AI Summary
Researchers at Ontinue disclosed TWINLOOT, a previously undocumented Python implant framework hardened with PyArmor that conducts its entire C2 operation through trusted Microsoft services — routing tasking through SharePoint Online files and communicating via Microsoft Teams — to evade network-based detection. The modular implant steals credentials and achieves lateral movement while blending into legitimate Microsoft 365 traffic. Security teams relying on network anomaly detection must augment controls with behavioral analysis of SharePoint and Teams API activity.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →