logo

Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic

ID: 46d0bdd4-112a-58c6-840c-a40187843967

STIX ID: report--46d0bdd4-112a-58c6-840c-a40187843967

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-06-16

Date Updated: 2026-07-23

...
...

Symantec researchers observed a campaign where DragonForce operators (linked to Scattered Spider affiliates) compromised a major US services company, deployed DragonForce ransomware and a custom Go backdoor called Backdoor.Turn, and hid C2 traffic by piggybacking on Microsoft Teams infrastructure (using anonymous Teams tokens, Microsoft-operated TURN relays, and QUIC) so network monitors saw only legitimate Teams traffic, enabling prolonged access and potential data exfiltration or resale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.