TWINLOOT Microsoft services C2 implant activity
Malware Activity
Summary
Hide ▲
Show ▼
TWINLOOT is a newly disclosed Python implant that hides command-and-control inside Microsoft services, increasing the odds that malicious traffic blends into normal enterprise cloud activity. The malware uses SharePoint Online, Microsoft Teams TURN, and a headless Edge browser to move tasking, operator access, and Graph traffic. It also steals Windows credentials, supports reverse SOCKS5 pivoting, and enables lateral movement and persistence on infected hosts.
Related Happenings
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware Activity
H score31
First: 09.07.2026 21:08
Last: 09.07.2026 21:08
Sources 1
About this happening:
The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware ActivityAbout this happening: The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
USB-spreading clipboard-stealing malware targeting cryptocurrency wallets
Malware Activity
H score27
First: 18.06.2026 19:20
Last: 18.06.2026 19:20
Sources 1
About this happening:
A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...
USB-spreading clipboard-stealing malware targeting cryptocurrency wallets
Malware ActivityAbout this happening: A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware Activity
H score29
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware ActivityAbout this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
Campaign
H score32
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
CampaignAbout this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Timeline
-
18.08.2026 15:38 2 articles · 1h ago
Researchers disclose TWINLOOT implant abusing SharePoint and Teams
Initial DisclosureOntinue disclosed TWINLOOT, a PyArmor-hardened Python implant that routes command-and-control through trusted Microsoft services by using SharePoint Online file dead-drops via the Microsoft Graph API and WebRTC DataChannels relayed by Microsoft Teams TURN servers. The implant drives Graph traffic from a headless instance of the victim's Edge browser, can steal Windows credentials with fake lock screens, and supports reconnaissance, discovery, screenshot capture, and persistence.
Show sources
- TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks — thehackernews.com — 18.08.2026 15:38
- TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks — thehackernews.com — 18.08.2026 15:38