In today's ever-evolving cyber threat landscape, we uncover a fascinating and concerning development involving the notorious DragonForce hacking group. This article delves into their recent activities, shedding light on a sophisticated method of concealing their malicious intentions.
The DragonForce Hackers and Their Stealthy Tactics
DragonForce, associated with the LockBit ransomware, has been in the spotlight for their innovative approach to cyberattacks. In a recent incident, they exploited Microsoft Teams' relay infrastructure to hide their command-and-control (C2) traffic, effectively masking their presence on a victim's network.
What makes this particularly fascinating is the use of a custom Go-based remote access trojan (RAT) named Backdoor.Turn. This tool allows them to obtain anonymous visitor tokens from Microsoft's identity services and leverage legitimate Microsoft TURN relays to establish connections with their command-and-control servers.
Unveiling the Attack Timeline
The attack timeline reveals a well-planned and executed operation. It is suspected that initial access was gained through a vulnerability in an SQL or MS-SQL server, although the specific flaw remains unknown. The attackers then deployed a PowerShell command, disguised as a tech support hotfix, to drop a ZIP archive containing a DLL side-loading attack. This attack allowed them to conduct reconnaissance, establish persistence, and disable security software using a Huawei driver.
One thing that immediately stands out is the use of a 'bring your own vulnerable driver' (BYOVD) technique. This method, combined with the exploitation of known vulnerabilities (such as CVE-2023-52271 and CVE-2025-61155), showcases the group's ability to adapt and leverage various attack vectors.
The Stealthy Nature of Backdoor.Turn
Backdoor.Turn's underlying mechanism relies on a stealthy C2 communication technique known as Ghost Calls. This technique, documented by Praetorian, allows the backdoor to establish a direct QUIC session with the attacker's server, effectively hiding its malicious activities from network defenders.
From my perspective, this level of sophistication indicates a highly skilled and organized hacking group. The ability to maintain covert access to compromised hosts for extended periods, as seen in this case, is a worrying trend. It highlights the need for robust security measures and continuous monitoring to detect and mitigate such advanced threats.
DragonForce's Evolution and Impact
The findings paint a picture of a hacking group that has evolved significantly. Hackledorb, the entity behind DragonForce, has transitioned from a conventional ransomware-as-a-service (RaaS) model to a structured cartel. Their adoption of highly advanced techniques, such as Backdoor.Turn and multi-vector BYOVD evasion, positions them as one of the most formidable ransomware groups currently active.
In conclusion, the DragonForce hackers' abuse of Microsoft Teams relays to hide their backdoor traffic is a stark reminder of the evolving nature of cyber threats. As threat actors continue to innovate and adapt, it is crucial for organizations to stay vigilant, invest in robust security measures, and continuously update their defense strategies. The cyber landscape demands a proactive and adaptive approach to ensure the safety and integrity of digital assets.