Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DragonForce Ransomware Exploits Microsoft Teams Servers

DragonForce Ransomware Exploits Microsoft Teams Servers

Posted on June 17, 2026 By CWS

A recent DragonForce ransomware attack has uncovered the use of Microsoft Teams relay servers for command-and-control operations, as reported by Symantec and Carbon Black’s threat hunter team. This innovative method highlights the group’s advanced tactics, reflecting their growing resourcefulness and organizational sophistication.

DragonForce’s Advanced Techniques

Established in 2023, the DragonForce group operates with a cartel-like structure, increasingly employing complex strategies. The newly detected malware, identified as Backdoor.Turn, is written in Go and disguises its communications as legitimate Microsoft Teams traffic. By obtaining an anonymous Teams visitor token and using Microsoft’s TURN relay, it establishes connections with the attacker’s actual command server, showcasing its sophistication.

This approach marks a first in malware development by leveraging the TURN relay infrastructure, an unprecedented move in ransomware attacks. The use of such bespoke tools by ransomware groups is notably rare, emphasizing DragonForce’s unique capabilities.

Impact on Targeted Firms

In a specific incident, DragonForce targeted a U.S. services company, likely compromised through a vulnerability in SQL or MSSQL servers. The attackers are believed to have purchased access from an access broker, gaining network entry in December 2025. Utilizing DLL sideloading, they executed additional malware from remote servers, ensuring persistence and security circumvention.

The strategy included reconnaissance and exploiting known driver vulnerabilities to achieve kernel-level access, allowing them to terminate security processes and deploy the ransomware for data encryption and exfiltration.

Maintaining Control and Persistence

Backdoor.Turn plays a crucial role post-ransomware deployment, enabling the execution of commands, process creation, network scanning, and credential exfiltration from compromised systems. It facilitates lateral movement using stolen credentials, complicating detection efforts as security software registers only legitimate Teams server traffic.

The sophisticated tactics employed by DragonForce underscore the challenge faced by cybersecurity defenses in detecting and neutralizing such advanced threats.

As cyber threats continue to evolve, understanding these methods is essential for developing effective countermeasures and safeguarding critical infrastructures.

Security Week News Tags:Backdoor TURN, cyber attack, Cybersecurity, data breach, DragonForce, Hacking, Malware, Microsoft Teams, Ransomware, security threat

Post navigation

Previous Post: Top Attack Surface Exposures to Watch in 2026
Next Post: Kodak Acknowledges Data Breach Amid ShinyHunters Threat

Related Posts

AI Tool Strengthens Satellite Security After Russian Cyberattack AI Tool Strengthens Satellite Security After Russian Cyberattack Security Week News
SolarWinds Patches Critical Web Help Desk Vulnerabilities SolarWinds Patches Critical Web Help Desk Vulnerabilities Security Week News
Cyber Insights 2026: External Attack Surface Management Cyber Insights 2026: External Attack Surface Management Security Week News
DragonForce Ransomware Exploits Microsoft Teams Servers BlueHammer Flaw Leveraged in Recent Ransomware Assaults Security Week News
CISA Demands Urgent SharePoint Security Fixes CISA Demands Urgent SharePoint Security Fixes Security Week News
Google Project Zero Tackles Upstream Patch Gap With New Policy Google Project Zero Tackles Upstream Patch Gap With New Policy Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Underground AI Service ‘Luciferus’ Promoted by Hackers
  • Microsoft’s AI Code of Conduct Prohibits Cyberattacks
  • CISA and NIST Issue Guide to Strengthen Identity Token Security
  • Microsoft Sets New AI Privacy Standards for Schools
  • Combatting Evolving Malware Infrastructure in SOCs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Underground AI Service ‘Luciferus’ Promoted by Hackers
  • Microsoft’s AI Code of Conduct Prohibits Cyberattacks
  • CISA and NIST Issue Guide to Strengthen Identity Token Security
  • Microsoft Sets New AI Privacy Standards for Schools
  • Combatting Evolving Malware Infrastructure in SOCs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark