Back to IntelRead Original Source
Intel Node
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
highransomware2026-06-18T13:30:07+00:00source excerpt
ransomwaremalware
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure. According to findings from Broadcom-owned Symantec and Carbon Black, the backdoor was deployed against a major U.S. services firm.