TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

A new wave of attacks is sweeping through corporate networks, exploiting a critical vulnerability in Microsoft’s SharePoint and Teams platforms. Dubbed “TwinLoot,” this sophisticated malware campaign has already compromised hundreds of companies worldwide, leaving sensitive data exposed to unauthorized access.

At its core, TwinLoot leverages the vulnerabilities inherent in collaborative tools like SharePoint and Teams to gain an initial foothold within a target network. By creating fake accounts or exploiting existing ones, attackers can quietly move laterally across domains, aggregating user credentials and escalating privileges along the way. This allows them to bypass traditional security controls and establish a lasting presence on the compromised network.

One of the most insidious aspects of TwinLoot is its ability to masquerade as legitimate traffic, making it difficult for even sophisticated security systems to detect. By mimicking the behavior of authorized users, attackers can seamlessly navigate the network, siphoning off sensitive information and hiding in plain sight. This not only enables them to evade detection but also sets the stage for more destructive attacks down the line.

The sheer scale of TwinLoot’s impact is staggering, with reports suggesting that hundreds of companies across various industries have already fallen victim to this campaign. The consequences are far-reaching: compromised credentials can be used to access sensitive data, while lateral movement allows attackers to spread malware and disrupt operations. In some cases, TwinLoot has even been linked to more nefarious activities, such as sabotage and intellectual property theft.

The underlying mechanisms driving TwinLoot’s success lie in the complexities of modern network architectures. With the rise of cloud-based services and collaboration tools, many organizations have inadvertently created pathways for lateral movement and privilege escalation. SharePoint and Teams, in particular, have become prime targets due to their widespread adoption and lax security settings. By exploiting these vulnerabilities, attackers can create a “super user” account that grants them unfettered access across multiple domains.

As the cybersecurity landscape continues to evolve, it’s clear that TwinLoot represents a serious threat to corporate networks worldwide. To mitigate this risk, organizations must prioritize vigilance and adapt their security strategies accordingly. This includes regularly monitoring collaboration tools for suspicious activity, implementing robust access controls, and conducting thorough vulnerability assessments to identify potential entry points. By staying one step ahead of attackers, companies can safeguard sensitive data and prevent the devastating consequences that TwinLoot has already wrought upon so many others.


Source: The Hacker News — 2026-08-18