TWINLOOT uses SharePoint, Teams, Azure and the victim’s own Edge browser to hide command-and-control traffic inside trusted Microsoft infrastructure.