[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4blM9CS8Fkps4bp-jGelhcU7jLadYosn1uZRR7EgyIg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"901b4570-a8f3-4c47-8b38-61b6ad1691ad","twinloot-exploits-trusted-microsoft-services-for-stealthy-credential-theft","62334025-f46f-4ed1-91d4-abb849423f0e","TWINLOOT Exploits Trusted Microsoft Services for Stealthy Credential Theft","TWINLOOT demonstrates a sophisticated abuse of legitimate, trusted Microsoft platforms (SharePoint Online and Teams) to disguise command-and-control traffic as normal enterprise activity, making traditional perimeter defenses ineffective. By blending malicious communications into approved business tools, the malware evades network-based detection that relies on blocklists or domain reputation. Credential theft via fake lock screens further highlights the danger of insufficient endpoint controls and user awareness. The ability to move laterally across networks compounds the initial compromise into a potential enterprise-wide breach. This attack underscores that trust in a platform's legitimacy is not a substitute for behavioral monitoring and least-privilege enforcement.","**Immediate actions:**\n- Audit and restrict OAuth application permissions for SharePoint and Teams to only those explicitly required by business roles.\n- Deploy conditional access policies that flag or block anomalous API call patterns to Microsoft 365 services from endpoints.\n- Enable Microsoft Defender for Cloud Apps (MCAS) policies to detect unusual SharePoint and Teams data access or exfiltration behaviors.\n\n**Long-term improvements:**\n- Implement network segmentation so that workstations cannot initiate lateral connections to other internal hosts without passing through monitored chokepoints.\n- Enforce phishing-resistant MFA (e.g., FIDO2) across all accounts to limit the impact of stolen Windows credentials.\n- Adopt an Endpoint Detection and Response (EDR) solution configured to alert on headless browser processes spawned outside of sanctioned administrative workflows.\n\n**Detection measures:**\n- Centralize and correlate Microsoft 365 Unified Audit Logs in your SIEM to baseline and alert on abnormal SharePoint\u002FTeams API usage volumes.\n- Monitor for fake lock screen indicators by alerting on unexpected credential prompt processes or unusual LSASS memory access events on endpoints.\n- Establish behavioral baselines for TURN server usage and alert on any endpoint initiating Teams relay connections outside of normal business hours or to unexpected destinations.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 4 – Controlled Use of Administrative Privileges","CIS Control 6 – Access Control Management","CIS Control 13 – Network Monitoring and Defense","CIS Control 16 – Application Software Security","NIST SP 800-53 AC-6 – Least Privilege","NIST SP 800-53 AC-17 – Remote Access","NIST SP 800-53 SI-4 – System Monitoring","NIST SP 800-53 SC-7 – Boundary Protection","NIST SP 800-53 IA-5 – Authenticator Management","MITRE ATT&CK T1557 – Adversary-in-the-Middle","MITRE ATT&CK T1021 – Remote Services (Lateral Movement)","MITRE ATT&CK T1102 – Web Service (C2 via Trusted Services)","GDPR Article 32 – Security of Processing","published","2026-08-18T14:21:30.775498+00:00","2026-08-18T14:21:30.404+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Ftwinloot-abuses-sharepoint-and-teams-to.html","twinloot-abuses-sharepoint-and-teams-to-steal-credentials-and-move-across-networ-77045d","TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":40,"name":41,"slug":42,"description":43,"color":44},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":46,"name":47,"slug":48,"description":49,"color":50},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]