By Interestana AI Editorial — AI-drafted, human-overseen. How we report
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity researchers have detailed a previously undocumented Python implant framework, codenamed TWINLOOT, which has been engineered to operate its entire command-and-control (C2) infrastructure within trusted Microsoft cloud services, specifically SharePoint Online and Microsoft Teams. This sophisticated approach allows the malware to blend seamlessly with legitimate network traffic, significantly complicating detection efforts by security professionals. Ontinue, a cybersecurity firm specializing in threat intelligence and incident response, disclosed these findings in a comprehensive technical report, shedding light on the novel tactics employed by this threat actor.
The TWINLOOT framework is characterized by its modular design and is further fortified using PyArmor, a tool designed to obfuscate Python code. This obfuscation makes it substantially more challenging for reverse engineers to analyze the malware's inner workings and understand its full capabilities. The primary objectives of TWINLOOT are to pilfer sensitive user credentials and to facilitate lateral movement across compromised networks, allowing attackers to expand their reach and access more valuable data. By strategically embedding its C2 operations within widely adopted Microsoft cloud platforms, TWINLOOT aims to bypass traditional security defenses that are often configured to block or flag connections to known malicious external C2 servers.
According to Ontinue's in-depth analysis, the framework's operational flow is managed through files stored within SharePoint Online. This means that tasking instructions for the implant are delivered via legitimate-looking documents, further enhancing its stealth. Communication channels are also reported to extend to Microsoft Teams, another ubiquitous collaboration tool, suggesting a multi-pronged approach to maintaining C2 persistence. The capabilities of TWINLOOT extend to the exfiltration of sensitive information and the execution of arbitrary commands on infected systems, granting attackers a high degree of control over compromised endpoints. The choice of SharePoint Online as a C2 vector is particularly noteworthy, given its widespread adoption in enterprise environments for document sharing and collaboration. This makes it an attractive and effective target for attackers seeking to establish a covert and persistent presence within an organization's network.
The implications of TWINLOOT's operation are profound for organizations that heavily rely on Microsoft 365 services. The malware's ability to operate with such a high degree of stealth within these trusted environments poses a significant and evolving threat to data security, intellectual property, and overall network integrity. Security teams are strongly advised to implement more robust monitoring and detection strategies that extend beyond traditional perimeter-based defenses. A critical focus should be placed on identifying anomalous activities within cloud-based collaboration tools like SharePoint and Teams, looking for unusual file access patterns, unexpected data transfers, or suspicious command execution. Further research into TWINLOOT's specific exploitation methods, the identity of the threat actor behind it, and its broader impact on enterprise security is ongoing, with a concerted effort to develop effective countermeasures against this novel and evasive threat.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.