HomeSecurityTWINLOOT: SharePoint and Teams Abused to Steal Credentials

TWINLOOT: SharePoint and Teams Abused to Steal Credentials

Cybersecurity researchers have uncovered a new malware framework, dubbed TWINLOOT, that uses Python and is designed to hide attackers' communications within legitimate Microsoft services. Ontinue discovered the tool in July 2026 as part of an investigation into an active cyberattack campaign.

Article Image: TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

TWINLOOT stands out because it does not rely solely on a traditional Command and Control server. Instead, it leverages SharePoint Online, Microsoft Teams, and the Edge browser , creating an infrastructure that can be extremely difficult to distinguish from normal corporate traffic.

SharePoint is becoming a command dead end

One of TWINLOOT's main channels is SharePoint. The malware uses the Microsoft Graph API and a folder as a dead-drop C2, where the attacker places commands. The infected system periodically checks this location, approximately every 15 seconds, looking for new instructions.

This option has a significant advantage for attackers: communication takes place through a service that businesses use every day, so malicious activity can be lost among normal connections to Microsoft cloud infrastructure

See also: SharePoint: CVE-2026-55040 Exploited after PoC Published

At the same time, TWINLOOT can use WebRTC DataChannels through Microsoft Teams TURN relays for more interactive communication with the operator.

Edge itself becomes a communication tool

Of particular interest is the use of Edge in headless mode, i.e. without a window being displayed to the user. TWINLOOT launches the browser and controls it via the Chrome DevTools Protocol, so that communication with Microsoft Graph is carried out by the victim's system itself.

This way, the traffic looks more like normal corporate browser activity and less like malware communicating with an external server.

password policy

Code theft and lateral movement

TWINLOOT is not limited to C2 communication. It has a mechanism for stealing credentials via a fake Windows lock screen. When the related function is activated, the user is presented with a screen that looks like the authentic one.

The first password entry is shown as incorrect, regardless of what the victim types. This may lead them to re-enter real password . Data is stored encrypted and transferred via SharePoint.

See also: SharePoint: RCE vulnerability exploited after public PoC exploit

The stolen information can then be used via a reverse SOCKS5 tunnel, allowing attackers to move within the internal network. The malware can facilitate connections to services such as SMB, RDP, WinRM, and MSSQL, significantly expanding the scope of an initial breach.

The attack begins with social engineering

According to Ontinue, the likely initial point of entry was a vishing attack via Microsoft Teams. The attacker posed as a support technician and convinced the employee to execute a PowerShell command.

The command downloaded a file containing a Python environment and a compiled payload of approximately 39 MB, which acted as a loader for TWINLOOT. The malware is protected with PyArmor, increasing the difficulty of analyzing its code.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Multiple persistence techniques

The framework also has mechanisms persistenceto maintain access to the system. Among other things, it uses COM scriptlets, techniques related to TaskCache, a self-update mechanism, and a particularly interesting technique with the NTUSER.MAN file.

The latter allows modification of the user profile via an offline registry hive, without the need for administrator privileges. Ontinue believes this is the first recorded malicious use of this method in a real-world incident.

See also: CVE-2026-58644: SharePoint Zero-day in CISA's KEV

Microsoft Surface Laptop Ultra with Nvidia RTX Spark chip

A wider wave of abuse of legitimate services

TWINLOOT is not an isolated example. Researchers have also identified other malware that leverages TURN relays, WebRTC, and headless browsers to hide their communication . Similar techniques have been linked to tools like Backdoor.Turn and msaRAT.

While it has not been definitively proven who is behind TWINLOOT, Ontinue sees similarities to STAC4749, which has been linked to Teams attacks and the Chaos ransomware.

The development shows a clear shift in attacker strategy: instead of always creating their own infrastructure, they are exploiting tools that already exist in an organization’s environment. For security teams, this means that detection can no longer rely solely on suspicious addresses or unknown servers, but must also look for unusual use of perfectly legitimate cloud services.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS