CYBERSECURITYTRACKER
TRACKING
Permanent story citation

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4585

As cited

Copy frozen at (site build).

threat intel

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Researchers disclosed TWINLOOT, a Python implant framework that operates its command-and-control infrastructure within Microsoft SharePoint and Teams. The malware leverages these trusted services to steal credentials and move laterally across networks, using PyArmor obfuscation to evade detection.

Why it matters: Organizations using Microsoft 365 are exposed to this threat; defenders must monitor for suspicious SharePoint and Teams activity patterns and review credential access logs in these environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Researchers disclosed TWINLOOT, a Python implant framework that operates its command-and-control infrastructure within Microsoft SharePoint and Teams. The malware leverages these trusted services to steal credentials and move laterally across networks, using PyArmor obfuscation to evade detection.

Why it matters: Organizations using Microsoft 365 are exposed to this threat; defenders must monitor for suspicious SharePoint and Teams activity patterns and review credential access logs in these environments.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary