Skip to main content
Back to Newswire
Security

Researchers detail TWINLOOT malware using Microsoft 365 services for control channels

Researchers detail TWINLOOT malware using Microsoft 365 services for control channels Image: Primary
Ontinue researchers disclosed TWINLOOT, a Python implant framework they found while investigating an active July 2026 campaign. The framework uses SharePoint Online file dead-drops through Microsoft Graph for tasking and can route interactive access through Microsoft Teams TURN relays. It can harvest credentials with fake Windows lock screens, execute commands and create a reverse SOCKS5 pivot into victim networks. Researchers assess its initial access method as Teams social engineering in which an operator posing as IT support persuades a target to run PowerShell.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire