Find notable cyber news and cases, enriched with sources, timelines, and signals.

TWINLOOT Microsoft services C2 implant activity

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

TWINLOOT is a newly disclosed Python implant that hides command-and-control inside Microsoft services, increasing the odds that malicious traffic blends into normal enterprise cloud activity. The malware uses SharePoint Online, Microsoft Teams TURN, and a headless Edge browser to move tasking, operator access, and Graph traffic. It also steals Windows credentials, supports reverse SOCKS5 pivoting, and enables lateral movement and persistence on infected hosts.

Related Happenings

SynkLoader malware distribution via Microsoft Teams phishing

Malware Activity
H score26 First: 21.08.2026 21:01 Last: 21.08.2026 21:01 Sources 1

About this happening: The SynkLoader malware family is being pushed through Microsoft Teams phishing to steal credentials with a fake Windows lock screen, giving attackers remote access...

SynkLoader Microsoft Teams help-desk phishing campaign

Campaign
H score35 First: 21.08.2026 21:01 Last: 21.08.2026 21:01 Sources 1

About this happening: The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...

GigaWiper / BLUERABBIT destructive Windows backdoor activity

Malware Activity
H score31 First: 09.07.2026 21:08 Last: 09.07.2026 21:08 Sources 1

About this happening: The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...

Edgecution malicious Microsoft Edge extension backdoor activity

Malware Activity
H score23 First: 24.06.2026 23:58 Last: 24.06.2026 23:58 Sources 1

About this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...

USB-spreading clipboard-stealing malware targeting cryptocurrency wallets

Malware Activity
H score27 First: 18.06.2026 19:20 Last: 18.06.2026 19:20 Sources 1

About this happening: A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...

Timeline

  1. 18.08.2026 15:38 2 articles · 13d ago

    Researchers disclose TWINLOOT implant abusing SharePoint and Teams

    Initial Disclosure

    Ontinue disclosed TWINLOOT, a PyArmor-hardened Python implant that routes command-and-control through trusted Microsoft services by using SharePoint Online file dead-drops via the Microsoft Graph API and WebRTC DataChannels relayed by Microsoft Teams TURN servers. The implant drives Graph traffic from a headless instance of the victim's Edge browser, can steal Windows credentials with fake lock screens, and supports reconnaissance, discovery, screenshot capture, and persistence.

    Show sources