logo

Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden

ID: 7c01eeb2-0a5d-5815-a91f-3ca68d719265

STIX ID: report--7c01eeb2-0a5d-5815-a91f-3ca68d719265

Feed Name: security.com

Threat Score
85/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Threat Hunter Team

...
...

Symantec describes a sophisticated DragonForce (Hackledorb) ransomware campaign that compromised a major U.S. services firm, used DLL sideloading and BYOVD/custom malicious drivers for privilege escalation and AV-killing, and deployed a novel Go-based backdoor (Backdoor.Turn) which hides C2 traffic by obtaining Teams visitor tokens and relaying through Microsoft TURN infrastructure before establishing QUIC sessions to attacker servers; the report includes attack chain details, multiple exploited drivers/CVEs, file and network IOCs, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.