Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Attackers Weaponize Microsoft Teams Relays to Stay Hidden

6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4

TLP:CLEAR
Active

SHA-256 Hash

Description

Attackers deploying DragonForce ransomware against a major U.S. services firm concealed their command-and-control traffic within Microsoft Teams relay infrastructure using Backdoor.Turn, a custom Go-based remote access trojan. This novel technique leverages anonymous Teams visitor tokens and TURN relay servers to mask malicious communications as legitimate Microsoft traffic. The intrusion lasted one to two months, beginning in December 2025 with exploitation of an SQL server vulnerability. Attackers employed sophisticated defense evasion tactics including DLL side-loading with VirtualBox executables and multiple Bring Your Own Vulnerable Driver techniques. They exploited a previously unknown vulnerability in Huawei's HWAuidoOs2Ec.sys driver, along with several other vulnerable drivers, to terminate security processes at kernel level. The campaign demonstrates DragonForce's evolution into a highly capable ransomware cartel with advanced operational maturity.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Attackers Weaponize Microsoft Teams Relays to Stay Hidden
Pattern Type
STIX
Confidence
75%
Valid From
Jul 17, 2026 02:00
Total Sightings
0
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.