DragonForce Hides Teams Traffic
Coverage from BleepingComputer, Tech Jacks Solutions Security Command Center, and others
Articles
3
Active Days
7
The Topic

This topic centers on DragonForce ransomware operations that use a custom backdoor, Backdoor.Turn, to hide command-and-control traffic inside Microsoft Teams relay infrastructure. The same campaign is tied to intrusion, credential theft, privilege escalation, data exfiltration, and ransomware deployment against at least one U.S. services company, with separate reporting that DragonForce also claimed an attack on a London production studio. The main significance is the abuse of trusted collaboration infrastructure to make malicious traffic look legitimate and harder for defenders to detect.
First Article: 06/14/26
Latest Article: 06/20/26
Summary
- DragonForce used a custom Go-based backdoor, Backdoor.Turn, to route command-and-control traffic through Microsoft Teams relay infrastructure.
- Researchers say this is the first known in-the-wild malware observed abusing Teams TURN relays in this way.
- The intrusion against a U.S. services company included reconnaissance, credential theft, lateral movement, privilege escalation, and data exfiltration before ransomware was deployed.
- The operators used multiple evasion techniques, including sideloading, rogue users, firewall changes, and vulnerable driver abuse.
- The campaign appears designed to keep attacker traffic blended into legitimate Microsoft infrastructure, making detection harder for security tools.
- Separate reporting shows DragonForce also claimed an attack on Ink, a London production studio, consistent with its double-extortion model.
History
This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.
