Bottom line: TWINLOOT poses a significant threat to organizations using Microsoft SharePoint and Teams, as it can steal credentials and move laterally across networks.
What's happening: Researchers from the University of Maryland have identified a previously undocumented Python implant framework dubbed TWINLOOT, which is designed to operate entirely within Microsoft services. TWINLOOT was first detected in June 2022, and has since been used to compromise SharePoint and Teams services. The framework is modular and can be used to steal credentials and move laterally across networks.
What to do: Security teams should ensure they are monitoring for suspicious activity related to TWINLOOT, and consider implementing additional security measures, such as two-factor authentication, to prevent credential theft. Organizations should also review their use of Microsoft SharePoint and Teams services and consider implementing additional security controls to prevent TWINLOOT from exploiting these services.