< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-18T18:08:20+05:30

TWINLOOT Malware Exploits SharePoint and Microsoft Teams for Credential Theft and Network Lateral Movement

TWINLOOT is a modular Python malware framework that leverages Microsoft SharePoint and Teams for command-and-control (C2) communication, credential theft via fake lock screens, and lateral movement across networks. It uses headless browsers and WebRTC data channels to evade detection while enabling interactive operator access and data exfiltration.

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.

"TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file

Read original article

*** END OF TRANSMISSION ***