news.mlab.sh
Back to the feed
ransomware

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

High
Image: The Hacker News
Summary

A U.S. services firm was targeted by the DragonForce ransomware group, who utilized a custom Go-based RAT, Backdoor.Turn, to conceal C2 traffic within Microsoft Teams relay infrastructure. The attackers leveraged a BYOVD technique, deploying a malicious driver and conducting reconnaissance, ultimately aiming to maintain persistent access to the compromised system. This sophisticated attack highlights the group's evolving capabilities and operational maturity.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.