Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

TWINLOOT: A Sophisticated Python Implant Framework Abuses SharePoint and Teams to Steal Credentials and Move Across Networks


Researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT, which abuses SharePoint and Teams to steal credentials and move across networks. The framework is capable of harvesting Windows credentials, offering reverse SOCKS5 pivots, executing arbitrary commands, and establishing persistence on the host. With its sophisticated capabilities and persistence mechanisms, TWINLOOT represents a significant escalation in the threat landscape, and organizations are urged to take immediate action to prevent such attacks.

  • TWINLOOT is a highly sophisticated Python implant framework that operates its entire command-and-control infrastructure inside trusted Microsoft services.
  • The framework is capable of harvesting Windows credentials, offering reverse SOCKS5 pivots, executing arbitrary commands, and establishing persistence on the host.
  • The framework uses four distinct methods to achieve long-term persistence on the victim's system.
  • The framework shares operational parallels with a cluster called STAC4749, which has a track record of orchestrating Teams voice phishing campaigns.
  • Organizations are urged to maintain robust endpoint security measures, including anti-malware software, regular software updates, and secure configuration of Microsoft services.
  • The emergence of TWINLOOT represents a significant escalation in the threat landscape, with its sophisticated capabilities making it a formidable opponent for cybersecurity professionals.



  • The cybersecurity landscape has recently witnessed the emergence of a highly sophisticated Python implant framework known as TWINLOOT. According to a recent disclosure by cybersecurity researchers, TWINLOOT is a modular and PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services. This particular framework represents a significant escalation in the tactics, techniques, and procedures (TTPs) employed by threat actors, who are increasingly leveraging legitimate Microsoft services to carry out their malicious activities.

    The researchers, who have been investigating an ongoing campaign involving the TWINLOOT framework, have revealed that the framework is capable of harvesting Windows credentials using pixel-perfect fake lock screens, offering a reverse SOCKS5 pivot into victim networks, executing arbitrary commands, and establishing persistence on the host. These capabilities demonstrate the depth of the threat posed by TWINLOOT, which can be used to carry out a wide range of malicious activities, including lateral movement, credential exfiltration, and command and control (C2) channel abuse.

    The researchers have also noted that the framework is equipped with a persistence mechanism, which uses four distinct methods to achieve long-term persistence on the victim's system. These methods include TypeLib COM scriptlet hijack, GhostTask-style TaskCache manipulation, self-update using a reobf.json manifest, and the use of an open-source tool called Swarmer. The latter method allows the framework to create stealthy Registry keys in the HKEY_CURRENT_USER (HKCU) hive without being detected by security software, even in the absence of administrator access.

    Furthermore, the researchers have discovered that the framework is capable of falling back to an EtherHiding-style mechanism to obtain the runtime configuration if the Azure Blob Storage dead drop method fails. This feature is currently unused in the build, suggesting that the framework is being actively developed and improved by its authors.

    The researchers have also noted that the framework shares operational parallels with a cluster called STAC4749, which has a track record of orchestrating Teams voice phishing campaigns to deploy Chaos ransomware. While the underlying implementation differs substantially, the similarities between the two frameworks highlight the evolving nature of threat actor tactics and the need for organizations to stay vigilant and proactive in their cybersecurity measures.

    In addition, the emergence of TWINLOOT serves as a reminder of the importance of maintaining robust endpoint security measures, including the use of anti-malware software, regular software updates, and secure configuration of Microsoft services such as SharePoint and Teams. Organizations that fail to implement these measures may be vulnerable to attacks like TWINLOOT, which can result in significant financial losses, reputational damage, and compromised intellectual property.

    In conclusion, the TWINLOOT framework represents a significant escalation in the threat landscape, with its sophisticated capabilities and persistence mechanisms making it a formidable opponent for cybersecurity professionals. As the threat actor landscape continues to evolve, it is essential for organizations to stay informed and proactive in their cybersecurity measures to prevent such attacks and minimize their impact.

    Researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT, which abuses SharePoint and Teams to steal credentials and move across networks. The framework is capable of harvesting Windows credentials, offering reverse SOCKS5 pivots, executing arbitrary commands, and establishing persistence on the host. With its sophisticated capabilities and persistence mechanisms, TWINLOOT represents a significant escalation in the threat landscape, and organizations are urged to take immediate action to prevent such attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/TWINLOOT-A-Sophisticated-Python-Implant-Framework-Abuses-SharePoint-and-Teams-to-Steal-Credentials-and-Move-Across-Networks-ehn.shtml

  • https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html

  • https://www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud


  • Published: Tue Aug 18 09:52:06 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us