www.security.com DragonForce Ransomware Exploits Microsoft Teams for Covert C2 Communications
Article Content
- •DragonForce ransomware uses Backdoor.Turn to hide C&C traffic in Microsoft Teams.
- •Attackers exploited vulnerabilities in SQL/MSSQL servers to gain initial access.
- •This is the first known malware to abuse Microsoft Teams' TURN infrastructure.
The DragonForce ransomware group has been observed using a custom malware, Backdoor.Turn, to conceal command-and-control (C&C) traffic within Microsoft Teams' relay infrastructure. This sophisticated technique allows attackers to mask their communications as legitimate Microsoft traffic, making detection difficult for network defenders. The attack targeted a major U.S. services firm, with the intrusion beginning in December 2025 after exploiting an SQL or MSSQL server vulnerability. The attackers maintained access for one to two months, utilizing a combination of Bring Your Own Vulnerable Driver (BYOVD) techniques and DLL hijacking to evade security measures. The malware was designed to obtain an anonymous Teams visitor token and establish a QUIC session to the attacker's C2 server. Researchers from Symantec have confirmed this is the first known instance of malware abusing Microsoft Teams' TURN infrastructure for such purposes. The incident highlights the evolving tactics of ransomware groups and the need for enhanced security measures against such sophisticated threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track DragonForce, Scattered Spider and Backdoor.Turn in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Emerging EDR Killer Tool Targeting Ransomware Groups A new malicious tool, referred to as the EDR killer, is being actively used by at least eight ransomware groups, including Blacksuit and Medusa, to disable endpoint detection and response (EDR) solutions. This tool is believed to be an evolution of the EDRKillShifter developed by RansomHub, which allows ransomware…
DragonForce Ransomware Targets Medical Department Store On September 10, 2026, a Medical Department Store in the United States was attacked by DragonForce ransomware, which has been monitored by Ransomware.live. The attack has raised significant concerns due to the sensitive nature of the healthcare sector, although specific details on the number of affected systems or…