New TWINLOOT Malware Abuses SharePoint and Teams for Stealthy Command-and-Control
Researchers uncover a modular Python implant that hides its C2 infrastructure inside trusted Microsoft services to steal credentials and move laterally.

Key Takeaways
- TWINLOOT is a modular Python implant hardened with PyArmor that abuses SharePoint Online and Microsoft Teams for C2 and lateral movement.
- The malware's use of trusted Microsoft services makes detection difficult, as traffic blends with legitimate organizational activity.
- No CVE or direct patch exists; mitigation involves monitoring for anomalous activity, enforcing least-privilege access, and reviewing Ontinue's indicators of compromise.
Related Security News

Chrome Web Store 'Poper Blocker' Extension Exfiltrates User Data
A browser extension named 'Poper Blocker' available on the Google Chrome Web Store has been identified as spyware that exfiltrates sensitive user data. Despite reports from researchers warning of its malicious nature, the extension maintained Google's seal of approval and was downloaded by millions of users before being removed.

RatHat Android Banking Trojan Console Leverages Gemini AI for Victim Targeting
Cleafy researchers have traced nearly 100 deployments of the RatHat Android banking trojan console since April 2026. The console, operated under a malware-as-a-service model, uses Google's Gemini AI to analyze collected data and identify higher-value victims. Infected devices face financial theft and potential exposure of sensitive data.



