logo

DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months

ID: 5e827af6-cc85-5222-b2d0-f726277e3bd9

STIX ID: report--5e827af6-cc85-5222-b2d0-f726277e3bd9

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-06-17

Date Updated: 2026-06-18

Author: Pierluigi Paganini

...
...

DragonForce, an evolved ransomware cartel active since 2023, compromised a major U.S. services firm and remained undetected for one to two months by routing command-and-control through Microsoft Teams TURN relays using a Go-based backdoor called Backdoor.Turn. The attackers used SQL/MSSQL access (possibly brokered), sideloaded malicious DLLs via legitimate executables, deployed BYOVD and custom malicious drivers for kernel evasion, conducted lateral movement and credential theft, and installed the backdoor post-ransomware—indicating persistence or resale of access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.