Threat Intelligence

New Malware 'TWINLOOT' Hides Inside Microsoft SharePoint and Teams to Steal Passwords

The Hacker News · 18 Aug 2026
Key Takeaway Ensure your business monitors unusual file-sharing or Teams activity patterns, not just external threats, since attackers are increasingly hiding inside trusted everyday tools like SharePoint.

Cybersecurity researchers have identified a previously unknown malware toolkit called TWINLOOT that uses everyday Microsoft business tools as a hiding place for its malicious activity. According to research firm Ontinue, TWINLOOT is a modular Python-based implant that has been specially hardened to resist analysis and detection. Instead of relying on unusual or suspicious network infrastructure, its entire command-and-control system operates through trusted Microsoft services, including SharePoint Online and Teams.

This approach is particularly concerning because SharePoint and Teams are core productivity tools used daily by millions of Australian businesses. Malicious traffic disguised as normal file activity in these platforms can blend in with legitimate business communications, making it much harder for security teams and automated tools to spot. Instructions for the malware are reportedly delivered through SharePoint file activity, allowing attackers to control infected systems while appearing to use standard, everyday cloud services.

While full technical details are still emerging, the discovery highlights a growing trend of attackers 'living off trusted platforms' rather than building their own suspicious infrastructure, which traditional security tools are better equipped to catch. Businesses using Microsoft 365 tools should be aware that legitimate-looking file and collaboration activity is not automatically safe.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.