TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Read full story on The Hacker News
Share
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
AI disclosure

Summary

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.