Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
ID: 46d0bdd4-112a-58c6-840c-a40187843967
STIX ID: report--46d0bdd4-112a-58c6-840c-a40187843967
Feed Name: The Register (Security)
Symantec researchers observed a campaign where DragonForce operators (linked to Scattered Spider affiliates) compromised a major US services company, deployed DragonForce ransomware and a custom Go backdoor called Backdoor.Turn, and hid C2 traffic by piggybacking on Microsoft Teams infrastructure (using anonymous Teams tokens, Microsoft-operated TURN relays, and QUIC) so network monitors saw only legitimate Teams traffic, enabling prolonged access and potential data exfiltration or resale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
