Cybersecurity researchers have uncovered a new Python-based implant framework called TWINLOOT that abuses trusted Microsoft services for command-and-control (C2) operations. The malware,…
Backdoor.TurnBroadcomC2 infrastructureCarbon Black
TWINLOOT is a modular Python implant hardened with PyArmor that uses SharePoint Online and Microsoft Teams TURN relays for command-and-control. It steals…
Ontinue's Cyber Defense Center discovered the TWINLOOT implant during an investigation into a campaign in July 2026. The company provided detailed technical…