TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.

“TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,” Ontinue said in a technical report shared with The Hacker News. “Tasking flows through SharePoint Online file

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with

Linux 0.11 rewritten in idiomatic Rust, boots in QEMU

Linux 0.11 rewritten in idiomatic Rust, boots in QEMU Source: Hacker News