Security researchers report that the DragonForce ransomware group uses Microsoft Teams relay infrastructure to hide malicious command-and-control (C2) communications during intrusions. Findings attributed the technique to a custom backdoor, reported as Backdoor.Turn, which runs as a Go-based remote access trojan. During an attack against a major U.S. services company, the malware reportedly obtains an anonymous “Teams visitor token” and leverages Microsoft Teams relay components to make its network activity blend in with legitimate-looking Teams traffic. Researchers say this approach helps conceal C2 exchanges from defenders that monitor for typical malware-to-server communications. Multiple outlets describe the method as the first known abuse of Microsoft Teams TURN (relay) infrastructure in this context. The reports also characterize DragonForce as a ransomware-as-a-service operation active since 2023, where affiliates receive tools and support in return for a share of ransom proceeds. Symantec and other observations connected to Broadcom-owned products underpin the analysis, and while the targeted organization’s name is not fully provided in the excerpts, the technique and tooling are described consistently across sources.
DragonForce ransomware group abuses Microsoft Teams relays to conceal command-and-control traffic
Security researchers report that the DragonForce ransomware group uses Microsoft Teams relay infrastructure to hide malicious command-and-control (C2) communications during intrusions. Findings attrib...
- DragonForce ransomware operators are observed using Microsoft Teams relay (TURN) infrastructure for command-and-control concealment.
- The activity is linked to a custom malware/backdoor named Backdoor.Turn, described as Go-based.
- Researchers say the malware obtains an anonymous Microsoft Teams visitor token to make malicious traffic appear legitimate to defenders.
- The technique is reported as the first known abuse of Microsoft Teams TURN infrastructure for this purpose.
- The intrusion described targets a major U.S. services company, and reporting cites Symantec findings (Broadcom-owned).
Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure. According to findings from Broadcom-owned Symantec and Carbon Black, the backdoor was deployed against a major U.S. services firm. The name of the company was
6 days agoDragonForce is the first ransomware operator to use this technique that was discovered last year.
1 week agoThe attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control. The post Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack appeared first on SecurityWeek.
1 week agoThe DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. DragonForce is a ransomware-as-a-service operation that has been active since 2023. The group provides affiliates with ransomware tools and supporting services in exchange for a share of ransom payments. First known abuse of Microsoft Teams TURN infrastructure “Backdoor.Turn obtains an anonymous Teams visitor token from … More → The post Cybercriminals mask malicious communications through Microsoft Teams relays appeared first on Help Net Security.
1 week agoCommand and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defenders
1 week agoDragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure. [...]
1 week ago
Thai pageant winners allege “taxi scam” after visit to Manila
Two Thai pageant winners who traveled to Manila for the Manila International Fashion Week allege they were robbed by peo...
Meta launches “Meta Glasses” under its own brand starting at $299, dropping Ray-Ban branding
Meta is introducing a new line of AI smart glasses branded as “Meta Glasses,” replacing the previous approach that relie...
Meta’s Threads reaches 500 million monthly users, rolls out new customization and community features
Meta says its Threads app has reached 500 million monthly active users, nearly three years after the platform launched a...