TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
TWINLOOT uses SharePoint, Teams TURN, and headless Edge for C2, steals Windows credentials, and opens SOCKS5 access into victim networks.
More info
