lab52 · Crawled Oct 2, 2026
Backdoors in the Dungeon – TURN & MQTT Abused by DragonForce
22 IoCs 1 Actors
Read original article ↗
AI Summary
DragonForce, a ransomware-as-a-service (RaaS) operation, has been observed deploying two backdoors that abuse legitimate infrastructure for command and control (C2) communications. The first backdoor operates in-memory and uses TURN servers, including Microsoft Teams infrastructure, to blend malicious traffic with legitimate traffic. The second backdoor ensures persistence via DLL sideloading and scheduled tasks, using both TURN and MQTT as redundant C2 channels. The malware employs encryption, obfuscation, and in-memory execution to evade detection and maintain access on compromised systems.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 22 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | f8eabae53e9dc8c529b6e38c58040ff28a07728cb5e896e16fb64e84bed5cd88 | Details → |
| SHA-256 | e9cd052f2d9514d40235ec04c9592f4274d0a4161b846e59bbb5a1a2c806a1c5 | Details → |
| SHA-256 | 6bbf10bcbef7ac5102b54c81137859891a3802dbacd888be90f990d50e18b0b4 | Details → |
| SHA-256 | 1657b22a553feae422dab77886ac60c06b8fad7cbd2cfaf482ba9066ba9922be | Details → |
| SHA-256 | 5275579f539812ff66d060e12c9b7e99a22c625018f1aae9c5642ab0ba058ccb | Details → |
| SHA-256 | c91852bfb8f1d428875595c14cfada8fb234483adb8c6ba78ca2b5ae2a0683e2 | Details → |
| SHA-256 | 01d638ddd9d780e934305422bc9ee8fa3a5b3163ba66514ae5e5a34ff24df9db | Details → |
| Filename | jli.dll | Details → |
| Filename | 25vtps.txt | Details → |
| Filename | dldwuibjn_chShllcodeTrn.txt | Details → |
| Filename | dldwuibjn_chShllcodeTrn.bin | Details → |
| Filename | rvsdiqw.txt | Details → |
| IP | 188[.]190[.]4[.]111 | Details → |
| IP | 62[.]164[.]177[.]145 | Details → |
| IP | 217[.]156[.]8[.]181 | Details → |
| Domain | accesscapfunding[.]com | Details → |
| Domain | paigeinfull[.]com | Details → |
| Domain | cncluxurywater[.]com | Details → |
| Domain | printpro[.]com[.]pl | Details → |
| Domain | pymsolutions[.]com[.]ar | Details → |
| Domain | whapido[.]com[.]ar | Details → |
| Domain | prolabgest[.]it | Details → |
MITRE ATT&CK TTPs 51 techniques
T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1052.001 Exfiltration over USB · Exfiltration T1053 Scheduled Task/Job · Execution T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1080 Taint Shared Content · Lateral Movement T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1134.001 Token Impersonation/Theft · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1202 Indirect Command Execution · Defense Evasion T1210 Exploitation of Remote Services · Lateral Movement T1218.002 Control Panel · Defense Evasion T1219 Remote Access Software · Command And Control T1222 File and Directory Permissions Modification · Defense Evasion T1484 Domain or Tenant Policy Modification · Defense Evasion T1484.001 Group Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1542 Pre-OS Boot · Defense Evasion T1543.002 Systemd Service · Persistence T1543.003 Windows Service · Persistence T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1569.002 Service Execution · Execution T1573 Encrypted Channel · Command And Control T1574.001 DLL Search Order Hijacking · Persistence T1586 Compromise Accounts · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1595 Active Scanning · Reconnaissance T1659 Content Injection · Initial Access