# Researchers detail TWINLOOT malware using Microsoft 365 services for control channels

_Tuesday, August 18, 2026 at 8:38 AM EDT · Security · Developing · Tier 1 — Major_

![Researchers detail TWINLOOT malware using Microsoft 365 services for control channels — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIrQ96TUVfZUEVto7SlNlTp_8P2270tmrpifBbd-F8vo3gQz3Na40YH60oRh2dEazLOZInJzCGa66bxl9t85Usl30eG_Db_yjMWup2eOM3BmaPhILk_Ihs-yo6AdB-DWG99L7OXK9bdD8Jygu2imWU71-Ap3bPtYLOgqu-vO2Zbr5egp6A5HNcXDSaa0o2/s1700-e365/windows-malware.jpg)

Ontinue researchers disclosed TWINLOOT, a Python implant framework they found while investigating an active July 2026 campaign. The framework uses SharePoint Online file dead-drops through Microsoft Graph for tasking and can route interactive access through Microsoft Teams TURN relays.

It can harvest credentials with fake Windows lock screens, execute commands and create a reverse SOCKS5 pivot into victim networks. Researchers assess its initial access method as Teams social engineering in which an operator posing as IT support persuades a target to run PowerShell.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html)

---
Canonical: https://techandbusiness.org/newswire/8uYMywgBYS_c9n0xkOlgn-
Retrieved: 2026-08-18T15:43:00.311Z
Publisher: Tech & Business (techandbusiness.org)
