news.mlab.sh
Back to the feed
threat-intel

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

High
Image: The Hacker News
Summary

Researchers have uncovered TWINLOOT, a sophisticated Python implant framework that leverages Microsoft services – specifically SharePoint Online and Teams TURN relays – to steal credentials and move laterally across networks. The framework employs a combination of techniques, including a headless Edge browser, reverse SOCKS5 proxies, and a fake lock screen to capture passwords, all while utilizing a persistence mechanism that creates a mandatory Windows profile hive to evade detection. This represents a novel approach to C2 communication and a significant escalation in the threat landscape, mirroring tactics used by groups like STAC4749, known for deploying Chaos ransomware via Teams voice phishing.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.