logo

Cybercriminals mask malicious communications through Microsoft Teams relays

ID: 148e5754-5ce1-5777-863b-d3b6493cd190

STIX ID: report--148e5754-5ce1-5777-863b-d3b6493cd190

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Sinisa Markovic

...
...

DragonForce, a ransomware-as-a-service group, conducted an intrusion against a U.S. services company that used DLL sideloading, BYOVD kernel-driver abuse, and a custom RAT called Backdoor.Turn which hid C2 traffic inside Microsoft Teams TURN relay infrastructure; attackers performed reconnaissance, credential theft, exfiltration and deployed ransomware, and Symantec published IoCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.