DragonForce ransomware operators are using a new backdoor that relies on Microsoft Teams relay servers for C&C.

DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure.

Custom malware routed communications through legitimate Microsoft services, making malicious activity look like routine corporate collaboration

DragonForce ransomware operators are using a new backdoor that relies on Microsoft Teams relay servers for C&C.

DragonForce-linked hackers used Backdoor.Turn to route C2 traffic through Microsoft Teams relay infrastructure during a U.S. firm attack.