// Microsoft 365MEDIUM
TWINLOOT, a Python-based implant, runs its entire command-and-control infrastructure through Microsoft 365 services (SharePoint and Teams) and Azure, authenticating via attacker-controlled Azure tenants. The campaign uses SharePoint as a dead drop and Teams TURN servers for reverse tunnels, evading logging in victim Entra ID and defeating signature-based detection.
// Get alerts for Microsoft 365