TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
thehackernews.com Aug 18, 2026

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

AI-summarised brief · reviewed before publication

Cybersecurity researchers uncovered TWINLOOT, a Python-based implant that hijacks Microsoft 365 services for command‑and‑control. The malware uses SharePoint Online dead‑drops, Microsoft Teams TURN servers, and a headless Edge browser to blend malicious traffic with legitimate activity. It harvests Windows credentials via fake lock screens, establishes a reverse SOCKS5 tunnel for lateral movement, and can execute arbitrary commands and maintain persistence. The tool was discovered during an investigation into a July 2026 campaign attributed to the Chaos ransomware group.

💡 Why It Matters

  • · TWINLOOT’s exploitation of trusted cloud services reveals a new vector that bypasses traditional perimeter defenses, forcing security teams to scrutinize legitimate Microsoft traffic for hidden malicious activity.