
New TWINLOOT Malware Abuses SharePoint and Teams for Stealthy Command-and-Control
Cybersecurity researchers at Ontinue have disclosed a previously undocumented Python implant framework called TWINLOOT. The malware is hardened with PyArmor and operates its entire command-and-control (C2) infrastructure through SharePoint Online and Microsoft Teams, making detection difficult by blending in with legitimate traffic. The framework is designed for credential theft and lateral movement across networks.
