logo

DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company

ID: aa6ffc3f-7afd-59eb-95d6-d70261b8b695

STIX ID: report--aa6ffc3f-7afd-59eb-95d6-d70261b8b695

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2026-06-16

Date Updated: 2026-06-18

...
...

Researchers reported that in 2025 a DragonForce ransomware campaign against a major US services firm used a Go-based RAT (Backdoor.Turn) to hide command-and-control traffic via Microsoft Teams TURN relays, exploited an undocumented Huawei driver vulnerability, removed security controls and created accounts for persistence, performed credential theft and lateral movement, exfiltrated data and ultimately deployed ransomware to encrypt victim machines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.