DragonForce Hackers: Uncovering the Microsoft Teams Relay Abuse (2026)

In today's ever-evolving cyber threat landscape, we uncover a fascinating and concerning development involving the notorious DragonForce hacking group. This article delves into their recent activities, shedding light on a sophisticated method of concealing their malicious intentions.

The DragonForce Hackers and Their Stealthy Tactics

DragonForce, associated with the LockBit ransomware, has been in the spotlight for their innovative approach to cyberattacks. In a recent incident, they exploited Microsoft Teams' relay infrastructure to hide their command-and-control (C2) traffic, effectively masking their presence on a victim's network.

What makes this particularly fascinating is the use of a custom Go-based remote access trojan (RAT) named Backdoor.Turn. This tool allows them to obtain anonymous visitor tokens from Microsoft's identity services and leverage legitimate Microsoft TURN relays to establish connections with their command-and-control servers.

Unveiling the Attack Timeline

The attack timeline reveals a well-planned and executed operation. It is suspected that initial access was gained through a vulnerability in an SQL or MS-SQL server, although the specific flaw remains unknown. The attackers then deployed a PowerShell command, disguised as a tech support hotfix, to drop a ZIP archive containing a DLL side-loading attack. This attack allowed them to conduct reconnaissance, establish persistence, and disable security software using a Huawei driver.

One thing that immediately stands out is the use of a 'bring your own vulnerable driver' (BYOVD) technique. This method, combined with the exploitation of known vulnerabilities (such as CVE-2023-52271 and CVE-2025-61155), showcases the group's ability to adapt and leverage various attack vectors.

The Stealthy Nature of Backdoor.Turn

Backdoor.Turn's underlying mechanism relies on a stealthy C2 communication technique known as Ghost Calls. This technique, documented by Praetorian, allows the backdoor to establish a direct QUIC session with the attacker's server, effectively hiding its malicious activities from network defenders.

From my perspective, this level of sophistication indicates a highly skilled and organized hacking group. The ability to maintain covert access to compromised hosts for extended periods, as seen in this case, is a worrying trend. It highlights the need for robust security measures and continuous monitoring to detect and mitigate such advanced threats.

DragonForce's Evolution and Impact

The findings paint a picture of a hacking group that has evolved significantly. Hackledorb, the entity behind DragonForce, has transitioned from a conventional ransomware-as-a-service (RaaS) model to a structured cartel. Their adoption of highly advanced techniques, such as Backdoor.Turn and multi-vector BYOVD evasion, positions them as one of the most formidable ransomware groups currently active.

In conclusion, the DragonForce hackers' abuse of Microsoft Teams relays to hide their backdoor traffic is a stark reminder of the evolving nature of cyber threats. As threat actors continue to innovate and adapt, it is crucial for organizations to stay vigilant, invest in robust security measures, and continuously update their defense strategies. The cyber landscape demands a proactive and adaptive approach to ensure the safety and integrity of digital assets.

DragonForce Hackers: Uncovering the Microsoft Teams Relay Abuse (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Madonna Wisozk

Last Updated:

Views: 5578

Rating: 4.8 / 5 (68 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Madonna Wisozk

Birthday: 2001-02-23

Address: 656 Gerhold Summit, Sidneyberg, FL 78179-2512

Phone: +6742282696652

Job: Customer Banking Liaison

Hobby: Flower arranging, Yo-yoing, Tai chi, Rowing, Macrame, Urban exploration, Knife making

Introduction: My name is Madonna Wisozk, I am a attractive, healthy, thoughtful, faithful, open, vivacious, zany person who loves writing and wants to share my knowledge and understanding with you.