DragonForce Ransomware Used Microsoft Teams to Conceal Command-and-Control Traffic in Attack on US Services Firm (infosecurity-magazine.com)
- Backdoor.Turn hides C2 traffic within Microsoft Teams TURN relay.
- Exploitation of an undocumented Huawei driver vulnerability (BYOVD).
- Attack targeted a US services firm, likely began in 2025.
"The DragonForce ransomware group infiltrated a major US services firm by hiding command-and-control traffic through Microsoft Teams TURN relay servers. Symantec and Carbon Black named the Go-based backdoor Backdoor.Turn; it obtained an anonymous Teams visitor token from Microsoft's Skype-backed identity services and used a legitimate TURN relay to establish a QUIC session with an attacker-controlled server. The attackers also exploited an undocumented Huawei driver vulnerability (later detailed by Huntress in March 2026) to mask their activity. The breach likely began via exploitation of a SQL or MSSQL server vulnerability."
no comments yet.