ransomware
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
High
Summary
DragonForce ransomware utilized a custom malware, Backdoor.Turn, to conceal command-and-control traffic by leveraging Microsoft Teams’ TURN protocol. This technique allowed the attackers to bypass traditional network defenses and operate within trusted networks. The operation, linked to the Scattered Spider group, involved exploiting vulnerabilities and deploying multiple drivers to gain elevated privileges and ultimately deploy the ransomware.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data