Frequency
2
occurrences
First Seen
June 16, 2026
Last Seen
June 17, 2026
Related Threat Clusters
-
DragonForce Ransomware Exploits Microsoft Teams for Covert C2 Communications
The DragonForce ransomware group has been observed using a custom malware, Backdoor.Turn, to conceal command-and-control (C&C) traffic within Microsoft Teams' relay infrastructure. This sophisticated technique allows…
13 articles · Updated June 16, 2026
Recent Intelligence Reports
- June 16 blog post — www.security.com · June 17, 2026
- DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden — Security · June 16, 2026
Related Entities
Hackledorb
Ransomware
Switzerland
Abyssworker
Backdoor.Turn
T1041 - Exfiltration Over C2 Channel
T1055 - Process Injection
T1068 - Exploitation for Privilege Escalation
T1071 - Application Layer Protocol
T1105 - Ingress Tool Transfer
T1218 - System Binary Proxy Execution
T1486 - Data Encrypted for Impact