A ransomware group, DragonForce, exploited Microsoft Teams to infiltrate a major U.S. services firm undetected for two months. They used a Go-based Remote Access Trojan (RAT), dubbed Backdoor.Turn, to hide command and control (C&C) traffic by masquerading as legitimate Microsoft Teams traffic. Their tactics included exploiting a vulnerability in a Huawei driver, altering system configurations, and creating new user accounts for ongoing access. The attackers focused on data exfiltration and system encryption. The incident exemplifies advanced cyber tradecraft, showcasing the sophistication of modern ransomware attacks.
DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company
CyberSIXT Evidence Panel
Primary Source
security.com
Threat Actor
🇲🇾 DragonForce
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Symantec spots DragonForce Backdoor.Turn using Teams TURN relay
cybersixt.com
-
DragonForce hides ransomware C2 via Microsoft Teams relays
cybersixt.com
-
DragonForce hides malware in Microsoft Teams via custom backdoor
cybersixt.com
-
DragonForce ransomware leverages Teams for new Backdoor.Turn C2
cybersixt.com
-
DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company
www.infosecurity-magazine.com