Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

DragonForce Ransomware Exploited Microsoft Teams to Hide Attack

June 16, 2026

Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code

June 16, 2026

SprySOCKS Backdoor Expands From Linux to Windows

June 16, 2026
Facebook X (Twitter) Instagram
Wednesday, June 17
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»DragonForce Ransomware Exploited Microsoft Teams to Hide Attack
News

DragonForce Ransomware Exploited Microsoft Teams to Hide Attack

Team-CWDBy Team-CWDJune 16, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A notorious ransomware group secretly infiltrated the network of a major company for up to two months by hiding command and control (C&C) traffic in Microsoft Teams, before unleashing their attack, researchers have warned.

The investigation report, published by Symantec and Carbon Black on 16 June, warned that attackers deployed DragonForce ransomware on the network of a “major US services firm.”

The cybercriminals used a Go-based Remote Access Trojan (RAT) to abuse Microsoft Teams’ TURN relay servers and mask command-and-control traffic. The backdoor, which researchers dubbed Backdoor.Turn, altered the traffic so all defenders could see was outbound connections to legitimate Microsoft Teams servers.

Backdoor.Turn was used to obtain an anonymous Teams visitor token from Microsoft’s Skype-backed identity services before using a legitimate Microsoft TURN relay to set up a connection. The attackers then ran a QUIC transport layer network protocol session which linked the infected machine to an attacker-controlled server.

The attackers also deployed what, at the time of the attack, was as an undocumented vulnerability in a Huawei driver to help mask their activity. The vulnerability was later detailed by Huntress in March 2026.

To help maintain persistence on the network the attackers altered configurations and systems. This included removing the Limit Blank Password security setting to allow for easy access to the compromised machines, creating new user accounts to maintain or gain additional access and modifying firewall rules to facilitate remote access and ensure C&C communication remained unhindered.

Read more: Why Ransomware Remains One of Cybersecurity’s Most Persistent and Costly Threats

These capabilities, combined with the capabilities of Backdoor.Turn – code execution, network scanning, credential-based lateral movement within the network and browser credential theft from compromised endpoints – allowed the attackers to secretly gain remote access to the network overtime.

All of this was abetted by stealthily hiding in C&C traffic in Microsoft Teams.

“The attackers in this campaign use exceptionally sophisticated cyber tradecraft. The configuration of Backdoor.Turn means that security products only see C&C traffic going to legitimate Teams servers, leaving defenders unaware that data is being siphoned away by malicious actors,” researchers warned in the blog post.

This incident took place in 2025, and the attackers were able to deploy DragonForce ransomware to exfiltrate data and encrypt the victim machines. There is no indication as to whether the victim paid the ransom to obtain the decryption key or encouraged the attackers to delete the data. Researchers believe the attack started when the attackers gained access to the victim network by exploiting a vulnerability in either an SQL or MSSQL server.

DragonForce has become one of the most notorious ransomware groups of recent times, accounting for a significant percentage of incidents and the group has claimed several major retailers as victims.

“The deployment of Backdoor.Turn, combined with their multi-vector BYOVD evasion, marks them as one of the most capable and persistent ransomware groups operating today,” researchers warned.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleVeeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
Team-CWD
  • Website

Related Posts

News

Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code

June 16, 2026
News

SprySOCKS Backdoor Expands From Linux to Windows

June 16, 2026
News

Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues

June 16, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

Is it time for internet services to adopt identity verification?

January 14, 2026

How cybercriminals are targeting content creators

November 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.