Attackers Weaponize Microsoft Teams Relays to Stay Hidden
June 16, 2026, 5:49 p.m.
Description
Attackers deploying DragonForce ransomware against a major U.S. services firm concealed their command-and-control traffic within Microsoft Teams relay infrastructure using Backdoor.Turn, a custom Go-based remote access trojan. This novel technique leverages anonymous Teams visitor tokens and TURN relay servers to mask malicious communications as legitimate Microsoft traffic. The intrusion lasted one to two months, beginning in December 2025 with exploitation of an SQL server vulnerability. Attackers employed sophisticated defense evasion tactics including DLL side-loading with VirtualBox executables and multiple Bring Your Own Vulnerable Driver techniques. They exploited a previously unknown vulnerability in Huawei's HWAuidoOs2Ec.sys driver, along with several other vulnerable drivers, to terminate security processes at kernel level. The campaign demonstrates DragonForce's evolution into a highly capable ransomware cartel with advanced operational maturity.
Tags
Date
- Created: June 16, 2026, 2:44 p.m.
- Published: June 16, 2026, 2:44 p.m.
- Modified: June 16, 2026, 5:49 p.m.
Indicators
- ce66b8221446c9b6d83f0ce6382f430e519601641e5daaaf1ca7a8a8806cb0b0
- 9335f61f8ad276d94455c5b6876fea48152c3cea759f2598c8108ee461fa5759
- e45b18c93d187aac5c4486f57483bc87580e15def82a312bfb377ff16eb96b22
- aea26980059ef2ad11e99556a4edfa1f8ec769fa9f06aa573b81bedf319954b5
- 6f9fbe29f8cc2788e2bc9d631e0eea2a8e9837076837b55838005a0e654f0a9e
- 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4
- f174c19902523dcf005fa044b6598403a5e5c0a5982398d1bc0dcc5ec1cd351b
- cd078957167e1af4de39aecdb981cd14156fa81d5a9c6ac51e74ae5b6199a12a
- 65ab49119c845801f29a57e8aa177146b2ffbd289d4278109b146f933380f951
- 82b37a92589dfd4d67ca87eb9e52ac8e682e8e60d2211f59074cd5ccc693013b
- 821da79d727351dd67ce5df7950e9a3de6647a3cf474bb3a093f67507fed92a6
- d20a3c928761fe00ac522eeb474612b5804cd9108453ea8591106d5d4428428e
- 8284c8676cc22c4b2e66826ac16986da7ddecba1f2776b16771be17bfdc45dc2
- d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923e
- 8a4033425d36cd99fe23e6faef9764fbf555f362ebdb5b72379342fbbe4c5531
- 048e18416177de2ead251abdf4d89837f6807c6aba4d5b1debe49adfdecbf05c
- 62.164.177.25
- http://192.36.27.51/TechSupV18Fix3.zip
Additional Informations
- projetosmecanicos.com.br
- glanz-gmbh.de
- mysimerp.net
- professionalhomebasedbusiness.com
- safefire.jo
- socialbizsolutions.com
- turnkeyaiagents.com
- comunidadesparentais.com.br
- United States of America