- What: DragonForce ransomware uses Microsoft Teams for covert C2
- Impact: Hides malicious traffic within legitimate Microsoft Teams infrastructure
Ransomware DragonForce ransomware uses Microsoft Teams for covert command and control June 16, 2026 Share By SC Staff As reported by Bleeping Computer, DragonForce ransomware has been observed using a novel technique to hide its command-and-control (C2) traffic by routing it through Microsoft Teams' relay infrastructure. The DragonForce ransomware operation, active since 2023 and linked to the Scattered Spider threat group, has employed custom Go-based malware dubbed "Backdoor.Turn". This malware abuses the Traversal Using Relays around NAT (TURN) protocol, which Microsoft Teams uses for message relay when direct connections fail. By obtaining an anonymous Teams visitor token and using legitimate Microsoft TURN relays, attackers can mask their C2 communications as normal Teams traffic, making detection significantly harder for defenders. This tactic was first conceptualized in 2025 by Praetorian with the "Ghost Calls" technique but Backdoor.Turn is the first known malware to implement it in the wild. The observed attack against a U.S. services company in December 2025 involved exploiting an SQL server flaw, followed by privilege escalation using multiple vulnerable drivers (BYOVD) to disable security tools. The Backdoor.Turn RAT was later deployed for persistence and data exfiltration before the final ransomware encryption. Researchers noted the attackers' sophisticated methods and have provided indicators of compromise. Source: Bleeping Computer An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Malware Malware distributed via Steam Workshop wallpapers SC Staff June 16, 2026 Kaspersky researchers have identified that malicious actors are exploiting the Steam Workshop platform, specifically through the Wallpaper Engine application, to distribute malware. Malware North Korean hackers use fake Microsoft alerts to deploy NarwhalRAT malware SC Staff June 16, 2026 The attackers send emails designed to raise alarm about potential account compromise and OTP abuse, tricking recipients into opening an attachment, according to the Genians Security Center. Phishing FBI warns of couriers collecting crypto scam payments SC Staff June 15, 2026 As reported by Bleeping Computer, the U.S. Federal Bureau of Investigation (FBI) has issued a warning regarding a trend in cryptocurrency investment scams, commonly known as "pig butchering" or "romance baiting." Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds