Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic
ID: bd30f9bd-6a54-596a-8141-a0b1451b4e6a
STIX ID: report--bd30f9bd-6a54-596a-8141-a0b1451b4e6a
Feed Name: cybersecurityNews.com
Symantec uncovered a campaign in which the Backdoor.TURN Go-based RAT leveraged Microsoft Teams TURN relay servers to hide C2 communications during a DragonForce ransomware intrusion against a major U.S. services firm; attackers used DLL sideloading, abused vulnerable drivers (including HWAuidoOs2Ec.sys and other CVE-linked drivers), deployed a custom malicious driver to kill security processes, and conducted reconnaissance, credential theft, lateral movement, and long-term persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
