www.security.com
DragonForce Ransomware Exploits Microsoft Teams for Covert C2 Communications
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The DragonForce ransomware group has been observed using a custom malware, Backdoor.Turn, to conceal command-and-control (C&C) traffic within Microsoft Teams' relay infrastructure. This sophisticated technique allows attackers to mask their communications as legitimate Microsoft traffic, making detection difficult for network defenders. The attack targeted a major U.S. services firm, with the intrusion beginning in December 2025 after exploiting an SQL or MSSQL server vulnerability. The attackers maintained access for one to two months, utilizing a combination of Bring Your Own Vulnerable Driver (BYOVD) techniques and DLL hijacking to evade security measures. The malware was designed to obtain an anonymous Teams visitor token and establish a QUIC session to the attacker's C2 server. Researchers from Symantec have confirmed this is the first known instance of malware abusing Microsoft Teams' TURN infrastructure for such purposes. The incident highlights the evolving tactics of ransomware groups and the need for enhanced security measures against such sophisticated threats.
Key Points: • DragonForce ransomware uses Backdoor.Turn to hide C&C traffic in Microsoft Teams. • Attackers exploited vulnerabilities in SQL/MSSQL servers to gain initial access. • This is the first known malware to abuse Microsoft Teams' TURN infrastructure.