TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
AI-summarised brief · reviewed before publication
Cybersecurity researchers uncovered TWINLOOT, a Python-based implant that hijacks Microsoft 365 services for command‑and‑control. The malware uses SharePoint Online dead‑drops, Microsoft Teams TURN servers, and a headless Edge browser to blend malicious traffic with legitimate activity. It harvests Windows credentials via fake lock screens, establishes a reverse SOCKS5 tunnel for lateral movement, and can execute arbitrary commands and maintain persistence. The tool was discovered during an investigation into a July 2026 campaign attributed to the Chaos ransomware group.
💡 Why It Matters
- · TWINLOOT’s exploitation of trusted cloud services reveals a new vector that bypasses traditional perimeter defenses, forcing security teams to scrutinize legitimate Microsoft traffic for hidden malicious activity.