<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Twinloot on BR Defense Center</title><link>https://brdefense.center/tags/twinloot/</link><description>Recent content in Twinloot on BR Defense Center</description><generator>Hugo</generator><language>pt-br</language><lastBuildDate>Tue, 18 Aug 2026 19:02:20 -0300</lastBuildDate><atom:link href="https://brdefense.center/tags/twinloot/index.xml" rel="self" type="application/rss+xml"/><item><title>Pesquisadores revelam novo malware TWINLOOT que usa serviços da Microsoft</title><link>https://brdefense.center/news/pesquisadores-revelam-novo-malware-twinloot-que-us/</link><pubDate>Tue, 18 Aug 2026 19:02:20 -0300</pubDate><guid>https://brdefense.center/news/pesquisadores-revelam-novo-malware-twinloot-que-us/</guid><description>&lt;p>Pesquisadores de cibersegurança divulgaram detalhes sobre um novo framework de malware em Python chamado TWINLOOT, projetado para operar sua infraestrutura de comando e controle (C2) utilizando serviços confiáveis da Microsoft. O TWINLOOT utiliza o SharePoint Online e o Microsoft Graph API para comunicação, tornando seu tráfego quase indistinguível da atividade legítima. O malware é capaz de coletar credenciais do Windows através de telas de bloqueio falsas, executar comandos arbitrários e manter persistência no sistema comprometido.&lt;/p></description></item></channel></rss>