CYBER● ELEVATEDAug 18 · Aug 18, 2026, 12:38 PM
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
The Hacker News
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. "TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services," Ontinue said in a technical report shared with The Hacker News. "Tasking flows through SharePoint Online file
GlobeAlert aggregates and classifies open sources; the story above belongs to its publisher. Summaries are machine-generated from the source text.
More in Cyber
CYBERnow[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIDark ReadingCYBERnow[Virtual Event] Building a Secure AI Strategy for the EnterpriseDark ReadingCYBER57m agoYou installed a VPN to hide from trackers . 85 % of them are trackers . gizmodo.com · United StatesCYBER1h agoOpenAI faces new lawsuits over Tumbler Ridge mass shooting tragedyAl Jazeera [en]