THREATOPS
THREAT OPSThreat News › TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

lowthehackernewsPublished 2026-08-18

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.

"TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html