{"id":1317,"date":"2026-09-01T14:48:14","date_gmt":"2026-09-01T09:18:14","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1317"},"modified":"2026-09-02T12:15:02","modified_gmt":"2026-09-02T06:45:02","slug":"twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/","title":{"rendered":"TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally"},"content":{"rendered":"<p>TWINLOOT shows how attackers can turn familiar Microsoft services into components of a covert attack framework. The Python implant uses SharePoint Online, Microsoft Graph, Teams infrastructure and Edge browser automation to conceal command-and-control activity.<\/p>\n<p>This Microsoft Graph malware does more than hide communications. It can capture Windows credentials, execute commands, maintain persistence and provide access to internal services. The campaign reinforces a difficult reality for defenders: trusted cloud traffic can carry malicious activity from a compromised endpoint.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStop Trusted Cloud C2 Abuse with Hexnode<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How Does TWINLOOT Compromise an Endpoint?<\/h2>\n<p>Ontinue discovered TWINLOOT while investigating an ongoing campaign in July 2026. Researchers assessed the initial access method as Microsoft Teams social engineering.<\/p>\n<p>An attacker impersonated IT support and persuaded a user to execute a <a href=\"https:\/\/www.hexnode.com\/blogs\/the-beginners-guide-to-powershell-scripting\/\">PowerShell command<\/a>. The command downloaded an archive containing a Python runtime and a compiled payload that loaded the implant.<\/p>\n<p>This delivery method allows the attacker to bypass technical controls by exploiting the user\u2019s trust in an internal support interaction. It also makes PowerShell malware detection critical, even when the command originates from an apparently legitimate conversation.<\/p>\n<h2>How TWINLOOT Abuses Microsoft Graph and Teams<\/h2>\n<p>TWINLOOT operates multiple command-and-control channels through Microsoft services. It uses SharePoint Online file dead drops for tasking through the Microsoft Graph API. The implant polls an attacker-controlled SharePoint drive, retrieves commands and returns collected data.<\/p>\n<p>Instead of connecting directly to Microsoft Graph, TWINLOOT launches the victim\u2019s Edge browser in headless mode. It controls the browser through the Chrome DevTools Protocol and uses it to communicate with Graph. This approach makes malicious traffic harder to separate from expected browser and Microsoft 365 activity.<\/p>\n<p>The implant also establishes a reverse SOCKS5 tunnel. Operators can route the tunnel directly to their infrastructure or through Microsoft Teams TURN relays using WebRTC DataChannels. The compromised endpoint then acts as a gateway into the internal network.<\/p>\n<p>Attackers can use this connection to reach services such as:<\/p>\n<ul>\n<li>SMB on port 445<\/li>\n<li>RDP on port 3389<\/li>\n<li>WinRM on ports 5985 and 5986<\/li>\n<li>MSSQL on port 1433<\/li>\n<\/ul>\n<p>To obtain credentials, TWINLOOT displays a realistic fake Windows lock screen. It captures the entered password, encrypts it and uploads it through the SharePoint channel. Operators can then use those credentials to access other systems through the SOCKS5 tunnel.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\r\n\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Why TWINLOOT Challenges Microsoft 365 Security<\/h2>\n<p>TWINLOOT combines trusted SaaS infrastructure with malicious endpoint behavior. A network tool that only checks destination reputation may see Edge, SharePoint and Teams traffic instead of an obvious command-and-control server.<\/p>\n<p>However, the endpoint still exposes behavioral signals. Defenders may observe unexpected PowerShell activity, pythonw.exe running from writable directories, headless Edge sessions, unusual persistence changes and connections from Python processes to internal services.<\/p>\n<p>Microsoft 365 security monitoring should therefore complement endpoint security. Teams and SharePoint audit data can provide cloud context, while endpoint telemetry reveals the processes generating the activity.<\/p>\n<h2>How Hexnode Can Support TWINLOOT Investigation and Response<\/h2>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can help security teams investigate suspicious endpoint processes and events associated with an intrusion. Its centralized threat and incident views provide context about endpoint activity and health. Defenders can also use investigation queries to search endpoint data for suspicious processes and related events.<\/p>\n<p>When analysts confirm malicious activity, Hexnode XDR provides response actions to isolate an affected device, kill a malicious process or quarantine a file. These actions can help contain the compromised endpoint while the security team investigates exposed credentials and lateral movement.<\/p>\n<p>Hexnode UEM adds preventive controls through Windows update management, application compliance policies and security configurations. Organizations can also integrate Hexnode with Microsoft Entra <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-conditional-access\/\">Conditional Access<\/a> to apply access decisions based on device compliance.<\/p>\n<p>These capabilities should form part of a broader response workflow. Security teams should also review Microsoft 365 audit logs, revoke suspicious sessions, reset exposed passwords and investigate every internal system accessed through the compromised host.<\/p>\n<h3>Stop Trusted Services From Becoming Attack Infrastructure<\/h3>\n<p>TWINLOOT demonstrates that trusted Microsoft services do not guarantee trusted activity. Attackers can combine social engineering, PowerShell execution, browser automation and cloud infrastructure to build a complete intrusion path.<\/p>\n<p>Enterprises need coordinated Microsoft 365 security, identity monitoring and endpoint security. This combined visibility helps teams identify the malicious process behind trusted traffic and stop one compromised endpoint from becoming a gateway across the network.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stop Trusted Cloud C2 Abuse<\/h5><p>Detect malicious endpoint activity, contain threats, and strengthen Microsoft 365 security with Hexnode XDR and UEM.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>TWINLOOT shows how attackers can turn familiar Microsoft services into components of a covert attack&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1343,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,19],"class_list":["post-1317","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-cloud-and-saas","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TWINLOOT Microsoft Graph Malware: SharePoint C2 Attack<\/title>\n<meta name=\"description\" content=\"TWINLOOT Microsoft Graph malware abuses SharePoint, Teams and Edge to steal credentials, maintain persistence and move across networks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TWINLOOT Microsoft Graph Malware: SharePoint C2 Attack\" \/>\n<meta property=\"og:description\" content=\"TWINLOOT Microsoft Graph malware abuses SharePoint, Teams and Edge to steal credentials, maintain persistence and move across networks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-01T09:18:14+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-02T06:45:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally\",\"datePublished\":\"2026-09-01T09:18:14+00:00\",\"dateModified\":\"2026-09-02T06:45:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/\"},\"wordCount\":728,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp\",\"articleSection\":[\"Malware\",\"Cloud and SaaS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/\",\"name\":\"TWINLOOT Microsoft Graph Malware: SharePoint C2 Attack\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp\",\"datePublished\":\"2026-09-01T09:18:14+00:00\",\"dateModified\":\"2026-09-02T06:45:02+00:00\",\"description\":\"TWINLOOT Microsoft Graph malware abuses SharePoint, Teams and Edge to steal credentials, maintain persistence and move across networks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TWINLOOT Microsoft Graph Malware: SharePoint C2 Attack","description":"TWINLOOT Microsoft Graph malware abuses SharePoint, Teams and Edge to steal credentials, maintain persistence and move across networks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/","og_locale":"en_US","og_type":"article","og_title":"TWINLOOT Microsoft Graph Malware: SharePoint C2 Attack","og_description":"TWINLOOT Microsoft Graph malware abuses SharePoint, Teams and Edge to steal credentials, maintain persistence and move across networks.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-01T09:18:14+00:00","article_modified_time":"2026-09-02T06:45:02+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally","datePublished":"2026-09-01T09:18:14+00:00","dateModified":"2026-09-02T06:45:02+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/"},"wordCount":728,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp","articleSection":["Malware","Cloud and SaaS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/","url":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/","name":"TWINLOOT Microsoft Graph Malware: SharePoint C2 Attack","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp","datePublished":"2026-09-01T09:18:14+00:00","dateModified":"2026-09-02T06:45:02+00:00","description":"TWINLOOT Microsoft Graph malware abuses SharePoint, Teams and Edge to steal credentials, maintain persistence and move across networks.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/TWINLOOT-Hides-C2-in-Microsoft-365-to-Steal-Credentials-and-Pivot-Internally.png?format=webp","width":1340,"height":700,"caption":"TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/twinloot-hides-c2-in-microsoft-365-to-steal-credentials-and-pivot-internally\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"TWINLOOT Hides C2 in Microsoft 365 to Steal Credentials and Pivot Internally"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1317"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1317\/revisions"}],"predecessor-version":[{"id":1321,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1317\/revisions\/1321"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1343"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}