Microsoft Teams Relay Abused to Stealthily Route Malware Communications
ID: 5be41e95-5c0a-537c-9aab-72effc269aa2
STIX ID: report--5be41e95-5c0a-537c-9aab-72effc269aa2
Feed Name: Cyber Press
Symantec investigated and attributed a targeted ransomware campaign by the DragonForce group that covertly tunneled command-and-control through Microsoft Teams TURN relays using a custom Go-based RAT (Backdoor.Turn). The intrusion leveraged an initial SQL/MSSQL compromise or purchased access, sideloaded a malicious DLL, deployed kernel-level BYOVD techniques including a purpose-built malicious driver (Abyss Worker) and exploited multiple signed-driver vulnerabilities to disable endpoint security, and maintained persistence for 1–2 months while exfiltrating credentials and mapping AD environments. The report includes detailed TTPs and multiple IoCs (SHA-256 hashes, an IP, and a URL).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
