Security
Researchers detail TWINLOOT malware using Microsoft 365 services for control channels
Image: Primary Ontinue researchers disclosed TWINLOOT, a Python implant framework they found while investigating an active July 2026 campaign. The framework uses SharePoint Online file dead-drops through Microsoft Graph for tasking and can route interactive access through Microsoft Teams TURN relays.
It can harvest credentials with fake Windows lock screens, execute commands and create a reverse SOCKS5 pivot into victim networks. Researchers assess its initial access method as Teams social engineering in which an operator posing as IT support persuades a target to run PowerShell.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
