DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company
ID: aa6ffc3f-7afd-59eb-95d6-d70261b8b695
STIX ID: report--aa6ffc3f-7afd-59eb-95d6-d70261b8b695
Feed Name: Infosecurity Magazine (News)
Threat Score
Researchers reported that in 2025 a DragonForce ransomware campaign against a major US services firm used a Go-based RAT (Backdoor.Turn) to hide command-and-control traffic via Microsoft Teams TURN relays, exploited an undocumented Huawei driver vulnerability, removed security controls and created accounts for persistence, performed credential theft and lateral movement, exfiltrated data and ultimately deployed ransomware to encrypt victim machines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
