Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Attackers drop DragonForce ransomware leveraging MS Teams relay systems

Attackers are deploying DragonForce ransomware using a novel backdoor that hides command-and-control traffic within the legitimate Microsoft Teams TURN relay infrastructure, making malicious communications appear as normal Teams activity. This technique abuses trusted services to evade traditional network detection controls like IP or domain filtering. The attackers operated undetected on the victim network for one to two months, demonstrating a significant evolution in ransomware tradecraft.
Read Full Article →

Ransomware , Malware Attackers drop DragonForce ransomware leveraging MS Teams relay systems June 17, 2026 Share By Steve Zurier (Adobe Stock) Attackers were observed deploying DragonForce ransomware against a major U.S. services firm, hiding command-and-control (C2) traffic inside Microsoft Teams’ own relay infrastructure using a new custom Go-based backdoor called Backdoor.Turn. In a June 16 blog post , researchers at Symantec and Carbon Black explained that the attackers could abuse trust in MS Teams so effectively that the only traffic network defenders could see was outbound connections to legitimate Microsoft Teams servers. The researchers said that attackers were on the victim network for between one and two months. Robert Coles, senior manager of threat intelligence security at Black Duck, said the case represents a clear example of how ransomware tradecraft has continued to evolve. “Frankly, it’s more about the abuse of trusted infrastructure than just a new piece of malware,” said Coles. Coles said what’s interesting here is the use of Microsoft Teams’ TURN relay capability — Traversal Using Relays around NAT — was designed to help systems communicate when direct connectivity isn’t possible. It essentially acts as a trusted intermediary, relaying traffic through Microsoft infrastructure so sessions still work reliably. “In this case, the attackers are leveraging that exact capability to mask command-and-control traffic,” said Coles. “By routing communications through legitimate Microsoft relay servers, everything looks like normal Teams activity from a network perspective. That makes it extremely difficult to detect using traditional controls like IP, domain, or reputation-based filtering.” Kieran Human, lead cybersecurity engineer at ThreatLocker, added that DragonForce has abused the trusted Micrsoft Teams relay infrastructure to hide communications between its malware and attacker-controlled systems, making malicious traffic look more like legitimate Teams activity. “The bigger danger is that attackers have now demonstrated they can hide their backdoor communications behind a service that organizations use and trust every day,” said Human. “It's another reminder that trust shouldn't be based just on the platform carrying the traffic. Behavior must be verified because attackers are finding novel ways to abuse legitimate services. Human said ThreatLocker has been monitoring DragonForce for some time. The group operates under a ransomware-as-a-service (RaaS) model, delivering ransomware tools and infrastructure to affiliates who carry out attacks and share stolen funds. Human added that DragonForce is known for its aggressive recruitment and public-facing approach, making them one of the important players in the cybercrime economy. An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More Steve Zurier Related Phishing Summer vacation scams surge, targeting travel industry SC Staff June 17, 2026 Check Point Research reported that in May 2026, the hospitality, travel, and recreation sector faced an average of 2,291 weekly cyberattacks per organization, a 24% increase from the previous month and more than double the volume seen in May 2023. Malware SprySOCKS backdoor expands to Windows with new variants SC Staff June 16, 2026 The Windows variants, WIN_DRV and WIN_PLUS, retain the core architecture of their Linux predecessor, including command-and-control (C2) protocols and encryption methods. Malware Malware distributed via Steam Workshop wallpapers SC Staff June 16, 2026 Kaspersky researchers have identified that malicious actors are exploiting the Steam Workshop platform, specifically through the Wallpaper Engine application, to distribute malware. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article