TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks Emmie Evans August 19, 2026

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.

“TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,” Ontinue said in a technical report shared with The Hacker News. “Tasking flows through SharePoint Online file

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top