Skip to main content
Home/Blog/Your Microsoft 365 Just Became the Attacker's Hiding Place. Meet TWINLOOT.
Cybersecurity

Your Microsoft 365 Just Became the Attacker's Hiding Place. Meet TWINLOOT.

A newly discovered malware framework called TWINLOOT hides its entire attack operation inside Microsoft SharePoint, Teams, and Edge — tools your business pays for every month. Here's what every business leader needs to know.

August 20, 2026·7 min read

Imagine an intruder who doesn't pick the lock on your front door. Instead, they borrow your house key, make a copy, and slip back in whenever they want — using your own entranceway, your own hallways, your own furniture to blend in. Your security cameras never trigger because everything looks exactly like you moving around your own home.

That's the threat cybersecurity researchers uncovered this week with TWINLOOT.

What Is TWINLOOT?

On August 18, 2026, researchers at Ontinue's Cyber Defense Center published their findings on a previously undocumented malware framework they discovered during an active investigation in July. They named it TWINLOOT — and it is unlike most threats your security team has been trained to spot.

Here's the core problem: TWINLOOT doesn't use attacker-controlled servers to run its operations. It doesn't register suspicious domains or route traffic to shady IP addresses. Instead, it conducts its entire command-and-control operation inside Microsoft 365 — using SharePoint Online, Microsoft Teams, and the victim's own Microsoft Edge browser.

Every command the attacker sends to the malware flows through SharePoint. Every piece of stolen data gets exfiltrated through SharePoint. The attacker's interactive access into the victim's network runs through Microsoft Teams infrastructure. And all of that traffic looks, at the network level, like legitimate Microsoft cloud activity — because it technically is.

According to researchers, this is the first known malware framework to combine all three of these techniques in a single tool.

How Attackers Get In

The initial attack is deceptively simple. Someone in your organization receives a message on Microsoft Teams from what appears to be an IT support contact. The message asks them to run a PowerShell command — often framed as a fix for a technical issue, a security update, or a configuration change.

One employee follows the instructions. That's all it takes.

The PowerShell command downloads a Python runtime and a large compiled payload onto the machine. Within minutes, TWINLOOT is running silently in the background, connecting to an attacker-controlled Azure tenant that your organization's security tools will never see.

The Fake Lock Screen You'll Never Recognize

One of TWINLOOT's most effective techniques is credential theft through a fake Windows lock screen.

When the attacker wants your employee's password, TWINLOOT displays a pixel-perfect replica of the standard Windows 10 or Windows 11 lock screen — populated with the employee's real account name and photo. It looks completely authentic because it's built from your own system's identity information.

The employee types their password. TWINLOOT captures it, encrypts it, and ships it off to the attacker via SharePoint. Then it displays an "incorrect password" message and lets the employee log in normally on their second attempt.

The employee assumes they mistyped. They move on. The attacker now has their credentials.

With those credentials, TWINLOOT opens a reverse tunnel into your network through Microsoft Teams infrastructure — giving the attacker access to internal file shares, remote desktop connections, and other systems that should only be accessible from inside your network.

Why Traditional Security Won't Catch This

Most enterprise security tools are built around one core assumption: malicious traffic goes to attacker-controlled destinations. Block the bad domains, flag the suspicious IPs, quarantine the known malware signatures.

TWINLOOT invalidates every piece of that logic.

There are no attacker-controlled domains in the traffic. There are no suspicious IP addresses — the traffic terminates at Microsoft's servers. There are no malware signatures in most antivirus databases, because this framework was unknown until last week. And because the attacker authenticates to their own Azure tenant rather than yours, your Microsoft 365 audit logs show nothing unusual.

As Shane Barney, CISO at Keeper Security, told CSO Online: "TWINLOOT works because defenders have been trained to treat Microsoft traffic as safe by default, and this malware was built to take full advantage of that."

This is what security professionals call "living off the land" — except instead of living off your operating system's built-in tools, the attacker is living off the cloud services your business relies on every single day.

Why Business Leaders — Not Just IT Teams — Need to Pay Attention

This isn't a story about a software bug that a vendor will patch. Microsoft's services are working exactly as designed. The problem isn't a flaw in SharePoint or Teams — it's that those services are being exploited in ways that expose a fundamental gap in how most businesses think about security monitoring.

For every business running Microsoft 365 — which is most of you — this threat is worth a direct conversation with your security team or IT partner. Not next quarter. Now.

Here are the questions I'd be asking:

First: Are you monitoring Microsoft 365 activity, not just the network perimeter?

Most organizations have decent perimeter monitoring — firewalls, web gateways, endpoint protection. Far fewer have meaningful visibility into what's happening inside their Microsoft 365 environment. What applications are accessing your SharePoint? What OAuth consents have been granted? What's the baseline for Graph API usage, and do you know when something deviates from it?

If your security team can't answer those questions with confidence, TWINLOOT would operate undetected in your environment.

Second: Do your employees know that Microsoft Teams messages from "IT support" can be fake?

TWINLOOT's entry vector is social engineering — not a zero-day exploit, not a sophisticated technical attack. One employee ran a PowerShell command they were asked to run on Teams. That's the whole breach.

Most security awareness training focuses on email phishing. Teams-based social engineering is a rapidly expanding attack surface that most training programs haven't caught up to. Does yours?

Third: What's your detection plan if the attack traffic looks like normal Microsoft activity?

This is the hardest question, and the most important one. Traditional signature-based detection won't catch TWINLOOT. Domain reputation tools won't flag Microsoft IP space. You need behavioral detection — the ability to identify anomalies in how your users interact with Microsoft 365, even when every individual action looks technically legitimate.

This means investing in Microsoft 365 security monitoring, Entra ID audit log analysis, and the capacity to establish behavioral baselines and detect deviations. It also means ensuring that Teams external access policies are appropriately restricted, that PowerShell execution is governed by policy, and that phishing-resistant MFA is enforced across the board.

The Bigger Pattern

TWINLOOT is a sign of where attacks are heading. Attackers are increasingly abandoning traditional infrastructure — domains, C2 servers, malware signatures — in favor of operating entirely within services that organizations already trust. We've seen this pattern in how attackers abuse OAuth tokens, exploit AI assistants, and now leverage collaboration platforms as command infrastructure.

The security tools built for yesterday's threat model are increasingly blind to this approach. The businesses that adapt — by investing in behavioral monitoring, identity security, and employee awareness — are the ones that will catch these threats before they cause real damage.

The businesses that don't will keep wondering why their antivirus didn't alert on anything.

What to Do Right Now

If you're running Microsoft 365, here's a practical starting point:

- Review your Microsoft 365 audit log configuration. Ensure unified audit logging is enabled and being actively monitored. - Restrict Teams external access policies to limit who can send messages to your employees from outside your organization. - Require signed scripts and restrict PowerShell execution policy for standard users. - Enforce phishing-resistant MFA across all Microsoft 365 accounts. - Conduct a review of OAuth application consents granted in your Entra ID environment. - Add Teams-based social engineering scenarios to your security awareness training.

None of this requires a seven-figure security budget. Most of it is configuration and policy — tools you already own, applied more deliberately.

TrustPoint Cyber helps organizations close exactly these kinds of gaps — the ones that live between what your security tools cover and what attackers are actually doing. If you're not sure whether your Microsoft 365 environment would catch something like TWINLOOT, let's find out before someone else does.

Get Protected

Ready to strengthen your security?

TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.