TWINLOOT uses SharePoint, Teams, Azure and the victim’s own Edge browser to hide command-and-control traffic inside trusted Microsoft infrastructure.
安全研究人员近日发出警告,一个新发现的Python恶意软件框架正通过微软服务来路由其大部分命令与控制(C2)流量,而这些服务正是防御人员日常预期会看到的正常流量。
TWINLOOT uses SharePoint, Teams, Azure and the victim’s own Edge browser to hide command-and-control traffic inside trusted Microsoft infrastructure. Security researchers are warning of a newly ...