// Alert

Microsoft 365 threat report

TWINLOOT, a Python-based implant, runs its entire command-and-control infrastructure through Microsoft 365 services (SharePoint and Teams) and Azure, authenticating via attacker-controlled Azure tenants. The campaign uses SharePoint as a dead drop and Teams TURN servers for reverse tunnels, evading logging in victim Entra ID and defeating signature-based detection.

// Get alerts for Microsoft 365