Cybersecurity researchers have uncovered a new malware framework, dubbed TWINLOOT, that uses Python and is designed to hide attackers' communications within legitimate Microsoft services. Ontinue discovered the tool in July 2026 as part of an investigation into an active cyberattack campaign.

TWINLOOT stands out because it does not rely solely on a traditional Command and Control server. Instead, it leverages SharePoint Online, Microsoft Teams, and the Edge browser , creating an infrastructure that can be extremely difficult to distinguish from normal corporate traffic.
SharePoint is becoming a command dead end
One of TWINLOOT's main channels is SharePoint. The malware uses the Microsoft Graph API and a folder as a dead-drop C2, where the attacker places commands. The infected system periodically checks this location, approximately every 15 seconds, looking for new instructions.
This option has a significant advantage for attackers: communication takes place through a service that businesses use every day, so malicious activity can be lost among normal connections to Microsoft cloud infrastructure
See also: SharePoint: CVE-2026-55040 Exploited after PoC Published
At the same time, TWINLOOT can use WebRTC DataChannels through Microsoft Teams TURN relays for more interactive communication with the operator.
Edge itself becomes a communication tool
Of particular interest is the use of Edge in headless mode, i.e. without a window being displayed to the user. TWINLOOT launches the browser and controls it via the Chrome DevTools Protocol, so that communication with Microsoft Graph is carried out by the victim's system itself.
This way, the traffic looks more like normal corporate browser activity and less like malware communicating with an external server.

Code theft and lateral movement
TWINLOOT is not limited to C2 communication. It has a mechanism for stealing credentials via a fake Windows lock screen. When the related function is activated, the user is presented with a screen that looks like the authentic one.
The first password entry is shown as incorrect, regardless of what the victim types. This may lead them to re-enter real password . Data is stored encrypted and transferred via SharePoint.
See also: SharePoint: RCE vulnerability exploited after public PoC exploit
The stolen information can then be used via a reverse SOCKS5 tunnel, allowing attackers to move within the internal network. The malware can facilitate connections to services such as SMB, RDP, WinRM, and MSSQL, significantly expanding the scope of an initial breach.
The attack begins with social engineering
According to Ontinue, the likely initial point of entry was a vishing attack via Microsoft Teams. The attacker posed as a support technician and convinced the employee to execute a PowerShell command.
The command downloaded a file containing a Python environment and a compiled payload of approximately 39 MB, which acted as a loader for TWINLOOT. The malware is protected with PyArmor, increasing the difficulty of analyzing its code.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Multiple persistence techniques
The framework also has mechanisms persistenceto maintain access to the system. Among other things, it uses COM scriptlets, techniques related to TaskCache, a self-update mechanism, and a particularly interesting technique with the NTUSER.MAN file.
The latter allows modification of the user profile via an offline registry hive, without the need for administrator privileges. Ontinue believes this is the first recorded malicious use of this method in a real-world incident.
See also: CVE-2026-58644: SharePoint Zero-day in CISA's KEV

A wider wave of abuse of legitimate services
TWINLOOT is not an isolated example. Researchers have also identified other malware that leverages TURN relays, WebRTC, and headless browsers to hide their communication . Similar techniques have been linked to tools like Backdoor.Turn and msaRAT.
While it has not been definitively proven who is behind TWINLOOT, Ontinue sees similarities to STAC4749, which has been linked to Teams attacks and the Chaos ransomware.
The development shows a clear shift in attacker strategy: instead of always creating their own infrastructure, they are exploiting tools that already exist in an organization’s environment. For security teams, this means that detection can no longer rely solely on suspicious addresses or unknown servers, but must also look for unusual use of perfectly legitimate cloud services.
