DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months
ID: 5e827af6-cc85-5222-b2d0-f726277e3bd9
STIX ID: report--5e827af6-cc85-5222-b2d0-f726277e3bd9
Feed Name: Security Affairs
DragonForce, an evolved ransomware cartel active since 2023, compromised a major U.S. services firm and remained undetected for one to two months by routing command-and-control through Microsoft Teams TURN relays using a Go-based backdoor called Backdoor.Turn. The attackers used SQL/MSSQL access (possibly brokered), sideloaded malicious DLLs via legitimate executables, deployed BYOVD and custom malicious drivers for kernel evasion, conducted lateral movement and credential theft, and installed the backdoor post-ransomware—indicating persistence or resale of access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
