DragonForce Hides Teams Traffic
Coverage from BleepingComputer, DigitalShield, and others

This topic centers on DragonForce ransomware operations that use a custom backdoor, Backdoor.
Turn, to hide command-and-control traffic inside Microsoft Teams relay infrastructure. The same campaign is tied to intrusion, credential theft, privilege escalation, data exfiltration, and ransomware deployment against at least one U.S. services company, with separate reporting that DragonForce also claimed an attack on a London production studio. The main significance is the abuse of trusted collaboration infrastructure to make malicious traffic look legitimate and harder for defenders to detect.
The main update is a stronger novelty claim: researchers now describe Backdoor.Turn as the first known in-the-wild malware abuse of Microsoft Teams TURN relays. Additional evasion details reinforce, rather than materially change, the existing assessment of the campaign.
