Home / Aug 19, 2026 / Story
0
#8 The Hacker News general August 18, 2026 at 12:38 UTC

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

By [email protected] (The Hacker News)

AI Summary

Researchers at Ontinue disclosed TWINLOOT, a previously undocumented Python implant framework hardened with PyArmor that conducts its entire C2 operation through trusted Microsoft services — routing tasking through SharePoint Online files and communicating via Microsoft Teams — to evade network-based detection. The modular implant steals credentials and achieves lateral movement while blending into legitimate Microsoft 365 traffic. Security teams relying on network anomaly detection must augment controls with behavioral analysis of SharePoint and Teams API activity.

Relevance score: 80.0/100

# More from August 19