0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

DragonForce Ransomware Used Microsoft Teams to Conceal Command-and-Control Traffic in Attack on US Services Firm (infosecurity-magazine.com)

· 41d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Backdoor.Turn hides C2 traffic within Microsoft Teams TURN relay.
  • Exploitation of an undocumented Huawei driver vulnerability (BYOVD).
  • Attack targeted a US services firm, likely began in 2025.

"The DragonForce ransomware group infiltrated a major US services firm by hiding command-and-control traffic through Microsoft Teams TURN relay servers. Symantec and Carbon Black named the Go-based backdoor Backdoor.Turn; it obtained an anonymous Teams visitor token from Microsoft's Skype-backed identity services and used a legitimate TURN relay to establish a QUIC session with an attacker-controlled server. The attackers also exploited an undocumented Huawei driver vulnerability (later detailed by Huntress in March 2026) to mask their activity. The breach likely began via exploitation of a SQL or MSSQL server vulnerability."

Discussion Matrix

0 segments

no comments yet.