Last Update: 09/19/2026 at 11:33 PM EST

DragonForce Hides Teams Traffic

Coverage from BleepingComputer, DigitalShield, and others

DragonForce Hides Teams Traffic topic image

This topic centers on DragonForce ransomware operations that use a custom backdoor, Backdoor.

Turn, to hide command-and-control traffic inside Microsoft Teams relay infrastructure. The same campaign is tied to intrusion, credential theft, privilege escalation, data exfiltration, and ransomware deployment against at least one U.S. services company, with separate reporting that DragonForce also claimed an attack on a London production studio. The main significance is the abuse of trusted collaboration infrastructure to make malicious traffic look legitimate and harder for defenders to detect.

Looking Back
7 Day Timeline
Jun 14Jun 15Jun 16Jun 18Jun 19Jun 20
History
06/29/2026

The main update is a stronger novelty claim: researchers now describe Backdoor.Turn as the first known in-the-wild malware abuse of Microsoft Teams TURN relays. Additional evasion details reinforce, rather than materially change, the existing assessment of the campaign.

All Articles3 articles
Additional3 articles · CI Score below 45
BleepingComputer / Bill Toulas
6/16/2026 • Cybersecurity (Privacy-Relevant) • General
DigitalShield / Alberto Payo
6/20/2026 • Cybersecurity (Privacy-Relevant) • General
Tech Jacks Solutions Security Command Center
6/14/2026 • Cybersecurity (Privacy-Relevant) • General