DragonForce Hackers: Uncovering the Microsoft Teams Relay Abuse for Stealthy Backdoor Operations (2026)

The Evolution of DragonForce Ransomware Tactics

The cybersecurity landscape is ever-evolving, and the latest development involving the notorious DragonForce ransomware group is a testament to this. This group, known for its innovative and aggressive tactics, has recently been exposed for its sophisticated abuse of Microsoft Teams' infrastructure, leaving security experts and organizations alike on high alert.

A Stealthy C2 Communication Channel

The hackers' use of a custom Go-based Remote Access Trojan (RAT), dubbed Backdoor.Turn, is a masterstroke in stealth. By leveraging Microsoft's own Teams relay infrastructure, they've created an almost invisible command-and-control (C2) channel. This allows them to operate under the radar, making detection a challenge for even the most vigilant network defenders.

Personally, I find this abuse of legitimate services particularly concerning. It highlights a growing trend where threat actors are exploiting trusted platforms to carry out malicious activities. This not only makes attribution difficult but also raises questions about the security of widely used collaboration tools.

The Art of Infiltration

The initial access method is still shrouded in mystery. While exploiting vulnerabilities in SQL or MS-SQL servers is a possibility, the involvement of an Initial Access Broker (IAB) cannot be ruled out. This ambiguity is a common tactic among sophisticated threat actors, making it harder to pinpoint the exact entry point and patch the vulnerability.

What many people don't realize is that the initial compromise is just the tip of the iceberg. The real danger lies in the subsequent actions, as seen here with the execution of a PowerShell command to drop a ZIP archive, disguised as a tech support hotfix. This is a classic social engineering tactic, preying on users' trust in technical support.

BYOVD: A New Evasion Technique

The 'Bring Your Own Vulnerable Driver' (BYOVD) technique is an intriguing development. By using vulnerable drivers, the attackers can evade detection and establish persistence on the compromised host. The use of a Huawei driver in this campaign is especially noteworthy, given its previous involvement in a large-scale malvertising campaign. This suggests a potential connection or a shared toolkit among threat actors.

A detail that I find fascinating is the timing of these events. The malvertising campaign using the Huawei driver is said to have occurred after the ransomware incident. This could indicate a sophisticated, long-term strategy where the attackers are continuously refining their tactics and reusing tools for different stages of their operations.

Ghost Calls: The Ultimate Stealth Mode

The implementation of the Ghost Calls technique, first documented by Praetorian, is a significant escalation. This stealthy C2 communication method allows the attackers to blend their activities with legitimate network traffic, making it incredibly difficult to identify malicious behavior.

What this really suggests is a highly skilled and well-resourced group. The ability to adopt such advanced techniques and integrate them into their operations showcases a level of sophistication that sets DragonForce apart from many other ransomware groups.

A New Era of Cybercrime Cartels

The transformation of Hackledorb, the group behind DragonForce, from a traditional RaaS model to a cartel structure is a significant development. This shift indicates a more organized and hierarchical approach, potentially allowing them to launch more targeted and impactful attacks.

In my opinion, this evolution in cybercrime structures is a worrying trend. It mirrors the sophistication of legitimate businesses, making it harder for law enforcement to dismantle these operations. The continuous development of new capabilities and the adoption of advanced techniques further solidify their position as a formidable threat in the cybercrime landscape.

DragonForce Hackers: Uncovering the Microsoft Teams Relay Abuse for Stealthy Backdoor Operations (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Dean Jakubowski Ret

Last Updated:

Views: 6183

Rating: 5 / 5 (50 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Dean Jakubowski Ret

Birthday: 1996-05-10

Address: Apt. 425 4346 Santiago Islands, Shariside, AK 38830-1874

Phone: +96313309894162

Job: Legacy Sales Designer

Hobby: Baseball, Wood carving, Candle making, Jigsaw puzzles, Lacemaking, Parkour, Drawing

Introduction: My name is Dean Jakubowski Ret, I am a enthusiastic, friendly, homely, handsome, zealous, brainy, elegant person who loves writing and wants to share my knowledge and understanding with you.