New Malware 'TWINLOOT' Hides Inside Microsoft SharePoint and Teams to Steal Passwords
Cybersecurity researchers have identified a previously unknown malware toolkit called TWINLOOT that uses everyday Microsoft business tools as a hiding place for its malicious activity. According to research firm Ontinue, TWINLOOT is a modular Python-based implant that has been specially hardened to resist analysis and detection. Instead of relying on unusual or suspicious network infrastructure, its entire command-and-control system operates through trusted Microsoft services, including SharePoint Online and Teams.
This approach is particularly concerning because SharePoint and Teams are core productivity tools used daily by millions of Australian businesses. Malicious traffic disguised as normal file activity in these platforms can blend in with legitimate business communications, making it much harder for security teams and automated tools to spot. Instructions for the malware are reportedly delivered through SharePoint file activity, allowing attackers to control infected systems while appearing to use standard, everyday cloud services.
While full technical details are still emerging, the discovery highlights a growing trend of attackers 'living off trusted platforms' rather than building their own suspicious infrastructure, which traditional security tools are better equipped to catch. Businesses using Microsoft 365 tools should be aware that legitimate-looking file and collaboration activity is not automatically safe.