ransomware
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
High
Summary
A U.S. services firm was targeted by the DragonForce ransomware group, who utilized a custom Go-based RAT, Backdoor.Turn, to conceal C2 traffic within Microsoft Teams relay infrastructure. The attackers leveraged a BYOVD technique, deploying a malicious driver and conducting reconnaissance, ultimately aiming to maintain persistent access to the compromised system. This sophisticated attack highlights the group's evolving capabilities and operational maturity.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
