Last Update: 08/01/2026 at 1:00 PM EST

DragonForce Hides Teams Traffic

Coverage from BleepingComputer, Tech Jacks Solutions Security Command Center, and others

Articles

3

Active Days

7

The Topic

DragonForce Hides Teams Traffic topic image

This topic centers on DragonForce ransomware operations that use a custom backdoor, Backdoor.Turn, to hide command-and-control traffic inside Microsoft Teams relay infrastructure. The same campaign is tied to intrusion, credential theft, privilege escalation, data exfiltration, and ransomware deployment against at least one U.S. services company, with separate reporting that DragonForce also claimed an attack on a London production studio. The main significance is the abuse of trusted collaboration infrastructure to make malicious traffic look legitimate and harder for defenders to detect.

First Article: 06/14/26

Latest Article: 06/20/26

Summary

  • DragonForce used a custom Go-based backdoor, Backdoor.Turn, to route command-and-control traffic through Microsoft Teams relay infrastructure.
  • Researchers say this is the first known in-the-wild malware observed abusing Teams TURN relays in this way.
  • The intrusion against a U.S. services company included reconnaissance, credential theft, lateral movement, privilege escalation, and data exfiltration before ransomware was deployed.
  • The operators used multiple evasion techniques, including sideloading, rogue users, firewall changes, and vulnerable driver abuse.
  • The campaign appears designed to keep attacker traffic blended into legitimate Microsoft infrastructure, making detection harder for security tools.
  • Separate reporting shows DragonForce also claimed an attack on Ink, a London production studio, consistent with its double-extortion model.

History

This topic is new, but as new articles are added to it this area will summarize shifts, changes and expansions of the issues.

Featured

Timeline: 7 Days

Jun 14Jun 15Jun 16Jun 18Jun 19Jun 20

Additional Articles