Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden
ID: 7c01eeb2-0a5d-5815-a91f-3ca68d719265
STIX ID: report--7c01eeb2-0a5d-5815-a91f-3ca68d719265
Feed Name: security.com
Symantec describes a sophisticated DragonForce (Hackledorb) ransomware campaign that compromised a major U.S. services firm, used DLL sideloading and BYOVD/custom malicious drivers for privilege escalation and AV-killing, and deployed a novel Go-based backdoor (Backdoor.Turn) which hides C2 traffic by obtaining Teams visitor tokens and relaying through Microsoft TURN infrastructure before establishing QUIC sessions to attacker servers; the report includes attack chain details, multiple exploited drivers/CVEs, file and network IOCs, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
