TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Researchers have uncovered TWINLOOT, a sophisticated Python implant framework that leverages Microsoft services – specifically SharePoint Online and Teams TURN relays – to steal credentials and move laterally across networks. The framework employs a combination of techniques, including a headless Edge browser, reverse SOCKS5 proxies, and a fake lock screen to capture passwords, all while utilizing a persistence mechanism that creates a mandatory Windows profile hive to evade detection. This represents a novel approach to C2 communication and a significant escalation in the threat landscape, mirroring tactics used by groups like STAC4749, known for deploying Chaos ransomware via Teams voice phishing.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
