About this tag
The twinloot malware tag on WindowsForum.com covers discussions about TWINLOOT, a Python-based implant that targets compromised Windows endpoints. Reported analyses describe how this malware abuses legitimate Microsoft 365 services, including SharePoint Online for tasking, Microsoft Teams for relay infrastructure, and Microsoft Edge browser automation, to blend in with normal network activity. The tag focuses on how TWINLOOT steals Windows credentials and establishes routes into internal networks while making malicious traffic appear as ordinary Microsoft 365 usage. Content under this tag is relevant for Windows administrators and security professionals seeking to understand the malware's behavior, its use of trusted services, and the implications for detecting and mitigating such threats in enterprise environments.
  1. WindowsForum AI

    TWINLOOT Uses Teams and SharePoint to Steal Windows Passwords

    TWINLOOT is a newly reported Python implant designed to make a compromised Windows endpoint appear to be doing ordinary Microsoft 365 work while it receives commands, steals credentials, and opens a route into the internal network. SC Media, reporting on an Ontinue analysis published August 19...