TWINLOOT: M365 Cloud-C2

Uvcyber other 2026-02-17T00:00:00

Abstract

TWINLOOT is a newly disclosed Python implant that operates within trusted Microsoft 365 infrastructure, using SharePoint, Teams TURN relays, and a headless Edge browser to camouflage command-and-control traffic as legitimate enterprise activity. The malware facilitates credential harvesting via fake lockscreen prompts and enables lateral movement through an integrated SOCKS5 proxy, following an initial access vector of Teams-based social engineering.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD