DragonForce Ransomware Exploits Microsoft Teams for Covert C2 Communications

DragonForce Ransomware Exploits Microsoft Teams for Covert C2 Communications

First seen 16 Jun 2026, 10:52 UTC SecurityBleepingcomputerInfosecurity-MagazineGbhackersFeeds2.Feedburner+7 89% similarity 69.6

Article Content

Browse articles
ThreatCluster

The DragonForce ransomware group has been observed using a custom malware, Backdoor.Turn, to conceal command-and-control (C&C) traffic within Microsoft Teams' relay infrastructure. This sophisticated technique allows attackers to mask their communications as legitimate Microsoft traffic, making detection difficult for network defenders. The attack targeted a major U.S. services firm, with the intrusion beginning in December 2025 after exploiting an SQL or MSSQL server vulnerability. The attackers maintained access for one to two months, utilizing a combination of Bring Your Own Vulnerable Driver (BYOVD) techniques and DLL hijacking to evade security measures. The malware was designed to obtain an anonymous Teams visitor token and establish a QUIC session to the attacker's C2 server. Researchers from Symantec have confirmed this is the first known instance of malware abusing Microsoft Teams' TURN infrastructure for such purposes. The incident highlights the evolving tactics of ransomware groups and the need for enhanced security measures against such sophisticated threats.

Key Points: • DragonForce ransomware uses Backdoor.Turn to hide C&C traffic in Microsoft Teams. • Attackers exploited vulnerabilities in SQL/MSSQL servers to gain initial access. • This is the first known malware to abuse Microsoft Teams' TURN infrastructure.

ThreatCluster AI How this analysis works

Timeline

2024-01-08
CVE-2023-52271 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-10
CVE-2025-1055 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-25
Public exploit for CVE-2025-61155 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2025-12-01
Attack on U.S. services firm begins
Attackers exploited an SQL or MSSQL server vulnerability to gain access to the network.
Infosecurity-Magazine
2026-03-01
Vulnerability in Huawei driver documented
Huntress researchers documented the vulnerability exploited by attackers in the Huawei driver used for evasion.
Security
2026-06-16
Attack disclosed by Symantec
Symantec published findings on the DragonForce ransomware's use of Microsoft Teams for C&C traffic concealment.
Bleepingcomputer

Community

Browse all →